Courseiva
Infrastructure →hardMultiple Choice

350-401 Infrastructure Practice Question

An engineer is deploying VXLAN with a distributed anycast gateway in a Cisco SD-Access fabric. Hosts in the same subnet are attached to different edge nodes. Which mechanism ensures that a host's default gateway MAC address is identical on every edge node while still allowing local forwarding?

⚠ Common exam trap

Many exam-takers confuse the fabric control plane's LISP endpoint mappings with gateway MAC distribution, when the anycast gateway MAC is simply a locally configured virtual MAC shared across edge nodes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A shared virtual MAC address is configured on the anycast SVI of every edge node in the fabric.

In a Cisco SD-Access fabric, distributed anycast gateway requires the same virtual MAC address configured on the anycast SVI of every edge node. This shared identity lets hosts keep a consistent default gateway while each edge node forwards locally, avoiding hairpinning through a central gateway and supporting host mobility across the fabric.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    A shared virtual MAC address is configured on the anycast SVI of every edge node in the fabric.

    Why this is correct

    The distributed anycast gateway uses the same virtual MAC on the anycast SVI of all edge nodes, so hosts see one consistent gateway identity regardless of attachment point. Each edge node can forward locally for hosts in its own subnet while the shared MAC preserves a stable default gateway, enabling seamless mobility and optimal forwarding without tromboning traffic to a central gateway.

  • ✗

    Each edge node uses a unique gateway MAC derived from its loopback0 address.

    Why it's wrong here

    Unique gateway MACs per edge node would force hosts to ARP for different gateway MACs, breaking the anycast gateway behavior. Hosts in the same subnet moving between edge nodes would see a different gateway MAC and could experience ARP cache inconsistencies. Distributed anycast gateway specifically requires a shared virtual MAC across edge nodes, so per-node derived MACs contradict the design.

  • ✗

    Edge nodes learn the gateway MAC from the fabric border node through VXLAN Group Policy Option headers.

    Why it's wrong here

    The VXLAN Group Policy Option header carries group policy tag and security metadata, not gateway MAC information. Border nodes provide external connectivity and policy enforcement, not gateway MAC distribution. The anycast gateway MAC is a static configuration on each edge node's SVI, independent of border node signaling.

  • ✗

    The fabric control plane assigns a single gateway MAC that is flooded to edge nodes via LISP map-register messages.

    Why it's wrong here

    LISP map-register and map-reply messages carry endpoint identifier-to-routing locator mappings, not gateway MAC assignments. Distributed anycast gateway MACs are configured locally on the anycast SVI, not distributed by the control plane. Relying on LISP messaging for MAC distribution mischaracterizes the protocol's role in the fabric.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.