350-401 Infrastructure Practice Question
An engineer is deploying VXLAN with a distributed anycast gateway in a Cisco SD-Access fabric. Hosts in the same subnet are attached to different edge nodes. Which mechanism ensures that a host's default gateway MAC address is identical on every edge node while still allowing local forwarding?
⚠ Common exam trap
Many exam-takers confuse the fabric control plane's LISP endpoint mappings with gateway MAC distribution, when the anycast gateway MAC is simply a locally configured virtual MAC shared across edge nodes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A shared virtual MAC address is configured on the anycast SVI of every edge node in the fabric.
In a Cisco SD-Access fabric, distributed anycast gateway requires the same virtual MAC address configured on the anycast SVI of every edge node. This shared identity lets hosts keep a consistent default gateway while each edge node forwards locally, avoiding hairpinning through a central gateway and supporting host mobility across the fabric.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A shared virtual MAC address is configured on the anycast SVI of every edge node in the fabric.
Why this is correct
The distributed anycast gateway uses the same virtual MAC on the anycast SVI of all edge nodes, so hosts see one consistent gateway identity regardless of attachment point. Each edge node can forward locally for hosts in its own subnet while the shared MAC preserves a stable default gateway, enabling seamless mobility and optimal forwarding without tromboning traffic to a central gateway.
- ✗
Each edge node uses a unique gateway MAC derived from its loopback0 address.
Why it's wrong here
Unique gateway MACs per edge node would force hosts to ARP for different gateway MACs, breaking the anycast gateway behavior. Hosts in the same subnet moving between edge nodes would see a different gateway MAC and could experience ARP cache inconsistencies. Distributed anycast gateway specifically requires a shared virtual MAC across edge nodes, so per-node derived MACs contradict the design.
- ✗
Edge nodes learn the gateway MAC from the fabric border node through VXLAN Group Policy Option headers.
Why it's wrong here
The VXLAN Group Policy Option header carries group policy tag and security metadata, not gateway MAC information. Border nodes provide external connectivity and policy enforcement, not gateway MAC distribution. The anycast gateway MAC is a static configuration on each edge node's SVI, independent of border node signaling.
- ✗
The fabric control plane assigns a single gateway MAC that is flooded to edge nodes via LISP map-register messages.
Why it's wrong here
LISP map-register and map-reply messages carry endpoint identifier-to-routing locator mappings, not gateway MAC assignments. Distributed anycast gateway MACs are configured locally on the anycast SVI, not distributed by the control plane. Relying on LISP messaging for MAC distribution mischaracterizes the protocol's role in the fabric.
Visual reference
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
Learn chapter
Network Access Control and AAA
Key term
Cisco SD-Access
Cisco Software-Defined Access is a network architecture that uses a central controller to automate and secure user and device access across an enterprise network.
Key term
Cisco Virtual Topology System
Cisco Virtual Topology System is a software-defined networking solution that creates and manages virtual network overlays across physical and virtual infrastructure for enterprise networks.
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.