Courseiva

CCNA Virtualization Questions

75 of 93 questions · Page 1/2 · Virtualization · Answers revealed

1
MCQhard

A network engineer is troubleshooting a Cisco SD-WAN deployment. The engineer notices that a branch site's vEdge router is not establishing control connections to the vSmart controller. The vEdge has the correct system IP and organization name. Which action should the engineer take first to verify connectivity?

A.Check the vEdge's configuration for the correct vBond IP address and ensure UDP port 12346 is open.
B.Ensure that the vEdge's WAN interface has a public IP address and can reach the internet.
C.Verify that the vSmart controller has the correct certificate and is in the whitelist.
D.Check the vManage GUI for the vEdge's serial number and ensure it is listed in the authorized devices.
AnswerA

The vEdge must first connect to the vBond orchestrator to learn about vSmart and vManage. The vBond IP address must be correctly configured, and UDP port 12346 must be open for the DTLS control connection. If the vEdge cannot reach vBond, it will not obtain the vSmart information and cannot establish control connections. This is the first step in troubleshooting.

Why this answer

In Cisco SD-WAN, a vEdge router must first establish a control connection to the vBond orchestrator. This requires the vBond IP address to be configured and UDP port 12346 to be open. Once the vEdge authenticates with vBond, it receives the list of vSmart controllers and can then establish control connections to them.

Therefore, the first troubleshooting step is to verify vBond reachability.

Exam trap

The trap here is focusing on vSmart or vManage configuration before verifying the initial vBond connection, which is the prerequisite for all other control connections.

2
Multi-Selecteasy

Which TWO of the following are benefits of using network virtualization with VXLAN? (Choose two.)

Select 2 answers
A.Enables Layer 2 extension across Layer 3 boundaries.
B.Eliminates the need for STP by using a centralized controller.
C.Uses only multicast for control plane learning.
D.Supports up to 16 million logical networks.
E.Provides native encryption for data in transit.
AnswersA, D

VXLAN tunnels Layer 2 over Layer 3.

Why this answer

VXLAN encapsulates Layer 2 frames in UDP packets over IP, allowing Layer 2 segments to be stretched across Layer 3 networks. This enables virtual machine mobility and multi-tenant environments without being constrained by physical network boundaries.

Exam trap

Cisco often tests the misconception that VXLAN eliminates STP or provides native encryption, but VXLAN is an overlay technology that still relies on the underlay network's STP and does not include encryption by default.

3
MCQeasy

A network administrator is configuring a Cisco Nexus 9000 switch to participate in a VXLAN EVPN fabric. The administrator needs to define the source IP address used for VXLAN tunnels. Which interface should be configured as the source for the VXLAN tunnel?

A.A switched virtual interface (SVI) for the management VLAN
B.A physical uplink interface
C.A port-channel interface
D.A loopback interface with a /32 mask
AnswerD

VXLAN tunnels use a loopback interface as the source to ensure high availability and stability. A /32 loopback is always up and not tied to a physical port, so the tunnel source remains reachable even if a link fails. This is the recommended design for VTEPs in a VXLAN EVPN fabric.

Why this answer

The VXLAN tunnel source should be a loopback interface with a /32 mask. This ensures a stable, always-up source IP address that is independent of physical link failures. Using a physical interface, SVI, or port-channel can cause tunnel instability if the underlying links or VLANs go down.

Exam trap

The trap here is choosing a port-channel or physical interface for redundancy, but a loopback is still the best practice for VTEP source because it is not tied to physical ports.

4
MCQmedium

A network engineer is configuring a Cisco Catalyst 9000 switch to support a VXLAN EVPN fabric. The engineer wants to enable the switch to act as a VTEP and perform VXLAN encapsulation and decapsulation. Which command must be configured to create the VXLAN tunnel interface?

A.interface vlan 1
B.interface tunnel 1
C.interface nve 1
D.interface vxlan 1
AnswerC

The 'interface nve 1' command creates a Network Virtualization Edge (NVE) interface, which is the logical interface used for VXLAN tunneling. Under this interface, you configure the source-interface and member VNIs. This is the standard way to enable VTEP functionality on Cisco platforms.

Why this answer

To enable VXLAN on a Cisco switch, you must create an NVE interface using the 'interface nve 1' command. This interface is responsible for VXLAN encapsulation and decapsulation. Other interface types like tunnel, vxlan, or vlan do not provide VXLAN functionality.

Exam trap

The trap here is assuming that VXLAN uses a generic tunnel interface, but Cisco implements VXLAN via the NVE interface.

5
MCQmedium

A network engineer is troubleshooting connectivity issues in a multi-tenant environment where each tenant's traffic is isolated using VRF-Lite. The engineer notices that tenants in the same VRF cannot communicate with each other across different access switches. Which design change should be implemented to enable inter-switch VRF communication?

A.Use the same VLAN for all tenants and rely on VLAN ACLs.
B.Create trunk links with 802.1Q subinterfaces on each switch and assign each subinterface to the appropriate VRF.
C.Configure static routes on each switch pointing to the next-hop IP in the global routing table.
D.Enable OSPF with a single area on all switches and redistribute between VRFs.
AnswerB

Creating an 802.1Q trunk with subinterfaces lets each switch or router terminate multiple VLANs on a single physical link, and each subinterface can be explicitly bound to a tenant's VRF. This gives each tenant an isolated routing table; the switch will route packets received on a subinterface using only the routes in that subinterface's assigned VRF. The trunk carries tagged frames for all tenants, but the VRF association ensures that traffic from tenant A's VLAN never enters tenant B's routing path, even though they share the same physical ports and trunk. This is a standard VRF-lite design for inter-switch VRF connectivity.

Why this answer

VRF-Lite requires 802.1Q trunking to extend Layer 3 VRF boundaries across switches. By creating subinterfaces on trunk links and assigning each subinterface to the appropriate VRF, traffic from the same VRF on different switches can be routed through the VRF-specific routing table, enabling inter-switch communication while maintaining isolation.

Exam trap

Cisco often tests the misconception that VRF-Lite can use the global routing table for inter-switch communication, but the trap here is that VRF-Lite requires explicit Layer 3 subinterfaces on trunk links to extend VRF boundaries, not just VLANs or static routes in the global table.

How to eliminate wrong answers

Option A is wrong because using the same VLAN for all tenants with VLAN ACLs does not provide Layer 3 VRF isolation; it only filters at Layer 2/3 within the global routing table, breaking the multi-tenant separation required. Option C is wrong because static routes in the global routing table would bypass VRF isolation, mixing tenant traffic and defeating the purpose of VRF-Lite. Option D is wrong because OSPF with redistribution between VRFs is complex and not supported in VRF-Lite without additional protocols like MP-BGP; VRF-Lite relies on static or connected routes within each VRF, not dynamic routing redistribution.

6
MCQhard

An organization is migrating from a traditional three-tier architecture to a leaf-spine fabric using VXLAN EVPN. The design requires that virtual machines can move between racks without IP address changes. Which technology must be enabled at the leaf switches to support this mobility?

A.Overlay Transport Virtualization (OTV).
B.VXLAN with EVPN control plane.
C.VRF-Lite with route redistribution.
D.MPLS L3VPN with BGP.
AnswerB

VXLAN with EVPN is the correct solution because it combines a Layer 2 data-plane overlay (VXLAN over UDP) with a modern BGP-based control plane (EVPN) that advertises MAC and IP reachability per VNI. This enables stretched Layer 2 forwarding across an IP underlay, allowing VMs to retain their IP and MAC addresses while migrating between switches, with EVPN providing MAC learning, ARP suppression, and multi-homing capabilities. It is purpose-built for constructing flexible, scalable network fabrics for internal mobility and is the standard approach for legacy-to-fabric migration scenarios.

Why this answer

VXLAN with EVPN control plane (B) is correct because it provides a Layer 2 overlay network that extends VLANs across the leaf-spine fabric, enabling virtual machine mobility without IP address changes. EVPN uses BGP to distribute MAC and IP address information, allowing the leaf switches to learn and forward traffic to VMs regardless of their physical location, which is essential for seamless VM migration between racks.

Exam trap

Cisco often tests the distinction between Layer 2 extension technologies (VXLAN EVPN) and Layer 3 VPNs (MPLS L3VPN), leading candidates to mistakenly choose MPLS L3VPN because it also uses BGP, but it cannot support Layer 2 mobility without IP changes.

How to eliminate wrong answers

Option A is wrong because Overlay Transport Virtualization (OTV) is a Cisco proprietary technology designed for interconnecting data centers over Layer 3 networks, not for intra-fabric VM mobility within a single leaf-spine architecture. Option C is wrong because VRF-Lite with route redistribution provides Layer 3 segmentation and routing but does not support Layer 2 extension or MAC mobility required for VM migration without IP changes. Option D is wrong because MPLS L3VPN with BGP is a Layer 3 VPN technology that operates at Layer 3 and cannot extend Layer 2 domains, making it unsuitable for preserving IP addresses during VM moves.

7
MCQmedium

An engineer is deploying a new branch office that must run multiple isolated routing domains on a single Cisco IOS-XE router. Each department requires its own routing table and overlapping IP addressing. The engineer plans to use VRF-Lite. Which configuration step is required to ensure that routes from one VRF do not leak into another?

A.Assign the VRF to the appropriate interfaces and configure a separate routing protocol instance within each VRF.
B.Enable MPLS LDP on all interfaces and redistribute the global routing table into each VRF.
C.Configure a single OSPF process and use different area IDs for each department.
D.Associate each VRF with a unique route distinguisher (RD) and route target (RT) in the BGP configuration.
AnswerA

VRF-Lite isolates routing by binding interfaces to a VRF and running an independent routing process per VRF. Without a routing instance inside the VRF, the router has no routes for that VRF, and without interface binding, traffic uses the global table. This combination provides the required isolation on a single device.

Why this answer

VRF-Lite achieves isolation by binding interfaces to a VRF and running a separate routing protocol instance inside each VRF. This creates independent routing and forwarding tables, allowing overlapping IP addresses and preventing route leakage. RDs, RTs, and MPLS are not needed on a single device; they are relevant only when extending VRFs across a provider core.

Exam trap

The trap here is assuming that VRF-Lite requires MPLS, RDs, or RTs for local isolation, when in fact interface binding and per-VRF routing processes are sufficient.

8
MCQmedium

A network engineer is deploying a Cisco SD-Access fabric. The design requires that endpoints in the same virtual network can communicate with each other even when they attach to different fabric edge nodes, while endpoints in different virtual networks remain isolated. Which control-plane component is responsible for registering endpoint IP-to-location mappings and answering fabric edge node queries?

A.Fabric control-plane node
B.Fabric intermediate node
C.Cisco DNA Center appliance
D.Fabric edge node
AnswerA

The fabric control-plane node runs LISP as the control plane for SD-Access, maintaining the endpoint ID-to-RLOC mapping database. Edge nodes register locally learned endpoints with it and query it to resolve remote endpoint locations before building VXLAN tunnels. This centralized mapping service enables same-virtual-network communication across edge nodes while keeping different virtual networks isolated through separate LISP instance IDs.

Why this answer

In Cisco SD-Access, the fabric control-plane node provides the LISP-based mapping database that stores endpoint ID-to-RLOC associations. Edge nodes register local endpoints and query this node to learn where remote endpoints reside, which enables communication between endpoints in the same virtual network across different edge nodes while preserving isolation between virtual networks.

Exam trap

The trap here is assuming Cisco DNA Center performs the runtime endpoint mapping lookups, when it actually handles design, policy, and automation while the fabric control-plane node owns the LISP mapping database.

9
MCQmedium

A network engineer is deploying a Cisco SD-Access fabric. The design requires that endpoints be authenticated and assigned to a VLAN and VRF based on their identity before any traffic is forwarded. Which Cisco SD-Access component is responsible for this function?

A.Cisco Identity Services Engine
B.Fabric border node
C.Fabric control plane node
D.Fabric edge node
AnswerA

Cisco ISE authenticates endpoints using 802.1X, MAC authentication bypass, or web authentication, and returns the VLAN and VRF (or SGT) assignment to the fabric edge node. This is the identity services function that enforces policy before forwarding.

Why this answer

Cisco ISE is the identity services component that authenticates endpoints and returns the VLAN and VRF assignment to the fabric edge node. The edge node then places the endpoint into the correct virtual network and applies group-based policy. Neither the control plane nor border nodes perform authentication or endpoint classification.

Exam trap

The trap here is assuming the fabric edge node or control plane node performs endpoint authentication and VLAN/VRF assignment, when that is actually the role of Cisco ISE.

10
Multi-Selecteasy

Which THREE of the following are components of a Cisco ACI fabric? (Choose three.)

Select 3 answers
A.Firewall
B.Spine switch
C.Router
D.APIC controller
E.Leaf switch
AnswersB, D, E

Spine switches form the fabric backbone.

Why this answer

The spine switch is a core component of a Cisco ACI fabric, forming the spine-leaf topology. Spine switches provide high-speed, non-blocking connectivity between leaf switches and handle all east-west traffic, relying on IS-IS as the routing protocol for fabric discovery and forwarding.

Exam trap

Cisco often tests the distinction between native fabric components (spine, leaf, APIC) and external devices (firewall, router) that can be integrated but are not part of the fabric itself, leading candidates to mistakenly include them as fabric components.

11
Drag & Dropmedium

Drag and drop the steps to configure OSPF on a Cisco router in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

OSPF configuration starts with enabling the OSPF process, then defining networks and areas.

12
MCQmedium

A network engineer is deploying virtual switching for a hypervisor host. The requirement is that virtual machines on the same host can communicate with each other using Layer 2 frame forwarding without any traffic leaving the physical NIC, and that VLAN tags be enforced per port profile. Which Cisco technology should be used to meet these requirements?

A.Cisco Nexus 1000V Virtual Ethernet Module (VEM)
B.Cisco Adaptive Security Virtual Appliance (ASAv)
C.Cisco Virtual Wide Area Application Services (vWAAS)
D.Cisco Cloud Services Router 1000V (CSR 1000V)
AnswerA

The Nexus 1000V VEM runs inside the hypervisor and performs local Layer 2 forwarding between virtual machines on the same host, so intra-host traffic never traverses the physical uplink. It also enforces port profiles and VLAN policies pushed from the Virtual Supervisor Module, which matches both stated requirements.

Why this answer

A virtual switch embedded in the hypervisor is needed so that same-host virtual machines exchange frames locally while still honoring VLAN and policy configuration. The Nexus 1000V VEM provides exactly this distributed virtual switching function, with the VSM supplying policy. The other listed products are virtual firewall, router and WAN optimization appliances, none of which perform virtual machine Layer 2 switching.

Exam trap

The trap here is assuming any virtual appliance that runs on a hypervisor can also switch traffic between virtual machines on that host.

13
Drag & Dropmedium

Drag and drop the steps to configure a site-to-site IPsec VPN on a Cisco router in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

IPsec VPN setup requires IKE phase 1, then phase 2 (transform set and crypto map).

14
MCQhard

A network engineer is troubleshooting a Cisco Nexus 9000 switch configured with VXLAN EVPN. The engineer notices that the switch is not learning remote MAC addresses from the EVPN control plane. The underlay is OSPF, and BGP EVPN peering is established with the spine switches. Which command should the engineer use to verify that the switch is receiving EVPN Type-2 routes?

A.show ip route vrf all
B.show l2route evpn mac all
C.show nve peers
D.show bgp l2vpn evpn
AnswerD

The command 'show bgp l2vpn evpn' displays the BGP EVPN table, including Type-2 routes (MAC/IP advertisement routes). If the switch is not receiving Type-2 routes, this command will show an empty table or missing entries for the expected MAC addresses. It is the primary command to verify EVPN route reception and is essential for troubleshooting control-plane learning.

Why this answer

To verify that the switch is receiving EVPN Type-2 routes, the engineer should use 'show bgp l2vpn evpn'. This command displays the BGP EVPN table, where Type-2 routes appear as '[2]:[MAC/IP]' entries. If these routes are missing, the switch will not learn remote MAC addresses via EVPN.

Checking the BGP EVPN table is the first step in troubleshooting control-plane learning issues.

Exam trap

The trap here is confusing data-plane verification commands like 'show nve peers' with control-plane verification commands like 'show bgp l2vpn evpn', or looking at the L2 route table instead of the BGP table.

15
MCQeasy

A network administrator is deploying a virtual switch on a Cisco UCS B-Series blade server. The administrator wants the virtual switch to be managed by Cisco UCS Manager and to support Cisco VM-FEX so that virtual machine traffic is visible to the upstream fabric interconnects. Which virtual switch technology meets these requirements?

A.Cisco Nexus 1000V Virtual Supervisor Module
B.Cisco Virtual Machine Fabric Extender in UCS Manager
C.VMware vSphere Standard Switch
D.Open vSwitch with Cisco ACI integration
AnswerB

VM-FEX in Cisco UCS Manager presents virtual interfaces from the fabric interconnect down to the hypervisor, so virtual machine traffic is treated like traffic from a physical adapter. It is managed directly in UCS Manager and provides the upstream visibility the administrator wants, satisfying both requirements in the scenario.

Why this answer

VM-FEX integrated with Cisco UCS Manager is the virtual switching technology that lets the fabric interconnect manage virtual interfaces and expose virtual machine traffic to upstream ports. It is administered from UCS Manager, which the administrator requires. Nexus 1000V, vSphere Standard Switch, and Open vSwitch do not provide UCS Manager-managed VM-FEX capability in this scenario.

Exam trap

The trap here is assuming any Cisco virtual switch integrates with UCS Manager, when VM-FEX is the specific feature that provides that management and visibility.

16
MCQmedium

A network engineer is deploying a Cisco SD-Access fabric using Cisco DNA Center. The design requires that wired users authenticate via 802.1X and be assigned to a specific overlay segment based on their department. Which Cisco SD-Access fabric component is responsible for authenticating the endpoint and assigning the endpoint to the correct overlay?

A.Cisco DNA Center
B.Fabric border node
C.Fabric edge node
D.Fabric control plane node
AnswerC

The fabric edge node is the first-hop device that connects wired endpoints to the fabric. It runs the host tracking database and acts as the authenticator for 802.1X, mapping the endpoint to the appropriate virtual network based on the Cisco DNA Center policy. When a user connects, the edge node performs authentication and assigns the endpoint to the correct overlay segment.

Why this answer

In Cisco SD-Access, the fabric edge node is the device where endpoints connect and are authenticated. It uses 802.1X, MAC authentication bypass, or web authentication to verify identity and then assigns the endpoint to a virtual network based on the policy defined in Cisco DNA Center. The control plane node handles LISP mappings, and the border node handles external connectivity, so they do not perform the authentication and assignment role.

Exam trap

The trap here is assuming that Cisco DNA Center performs the authentication, when it only defines policy and the edge node enforces it.

17
MCQhard

A network engineer is troubleshooting a Cisco Nexus 9000 switch configured for VXLAN EVPN. The engineer notices that the switch is not learning remote MAC addresses from other VTEPs. The underlay routing is working, and MP-BGP EVPN peering is established. Which configuration issue could prevent the switch from learning remote MAC addresses?

A.The BGP router ID is not unique.
B.The VNI is not mapped to the correct VLAN in the EVPN configuration.
C.The underlay OSPF cost is too high.
D.The switch is configured with a static VXLAN tunnel instead of a dynamic one.
AnswerB

For VXLAN EVPN to learn remote MAC addresses, the VNI must be mapped to the correct VLAN. If the mapping is missing or incorrect, the switch cannot associate incoming EVPN routes with the local VLAN, preventing MAC learning. This is a common misconfiguration that breaks overlay connectivity.

Why this answer

In VXLAN EVPN, the VNI must be mapped to the correct VLAN for the switch to associate EVPN routes with local VLANs and learn remote MAC addresses. If the mapping is missing or incorrect, the switch cannot install remote MACs into the MAC address table, even if EVPN peering is up and the underlay is functional.

Exam trap

The trap here is focusing on underlay or BGP peering issues when the problem is actually a local mapping mismatch between the VNI and VLAN, which is a common EVPN configuration oversight.

18
Multi-Selectmedium

A network architect is designing a VXLAN EVPN fabric on Cisco Nexus 9000 switches to replace a traditional three-tier data center design. The architect wants to use a distributed anycast gateway so that hosts can move between leaf switches without changing their default gateway. Which two statements correctly describe the anycast gateway design? (Choose two.)

Select 2 answers
A.Only the spine switches can host the anycast gateway function
B.The same gateway IP and MAC address are configured on every leaf switch that hosts the VLAN
C.Hosts must be reconfigured with a new default gateway each time they migrate
D.Each leaf switch must use a unique gateway MAC address to avoid duplicate MAC detection
E.The gateway MAC is a shared virtual MAC, typically derived from the reserved Cisco anycast gateway range
AnswersB, E

An anycast gateway uses the same virtual IP and virtual MAC on every leaf that participates in the VLAN, so a host keeps the same default gateway regardless of which leaf it attaches to. This is what enables seamless workload mobility without re-ARPing or changing host configuration when a virtual machine moves between racks.

Why this answer

A distributed anycast gateway places the same virtual gateway IP and virtual MAC on every leaf switch that hosts the VLAN. Hosts keep a consistent default gateway no matter which leaf they attach to, and ARP is answered locally on the attached leaf. This supports seamless workload mobility and avoids stretching traffic to a central gateway.

Exam trap

The trap here is assuming each leaf needs a unique gateway MAC, when the design deliberately shares one virtual MAC across all participating leaves.

19
MCQmedium

A network engineer is deploying a Cisco Nexus 9000 leaf-spine fabric with VXLAN EVPN. The design requires that all leaf switches act as VTEPs and that each leaf learn remote MAC addresses only from the fabric control plane rather than from data-plane flooding. Which configuration on the leaf switches accomplishes this requirement?

A.Configure `arp suppression` on all leaf switches so that ARP requests are answered locally without control-plane involvement.
B.Configure the NVE interface with `source-interface loopback0` and enable `host-reachability protocol bgp`.
C.Configure `flooding enable` globally on each leaf so unknown unicast frames are replicated to all VTEPs in the fabric.
D.Configure `ingress-replication protocol static` on the NVE interface with a list of all remote VTEP addresses.
AnswerB

Enabling BGP as the host-reachability protocol on the NVE interface causes the leaf to advertise and learn MAC/IP and IMET routes through EVPN, so remote MAC addresses are resolved from the control plane instead of flood-and-learn. The loopback source provides a stable VTEP address reachable across the underlay, which is required for the EVPN peering and for tunnel endpoints to be consistent.

Why this answer

The requirement is control-plane MAC learning across the VXLAN fabric. Binding the NVE interface to a loopback and enabling BGP as the host-reachability protocol makes the leaf a VTEP that exchanges EVPN MAC/IP and IMET routes with its peers. Remote MAC addresses are then resolved from BGP EVPN advertisements, eliminating flood-and-learn.

Flooding, static ingress replication, and ARP suppression alone cannot satisfy that control-plane requirement.

Exam trap

The trap here is assuming that enabling ARP suppression or flooding achieves control-plane MAC learning, when only the host-reachability protocol tied to BGP EVPN does that.

20
MCQmedium

A network engineer is configuring a Cisco CSR 1000v router to support a virtual routing and forwarding (VRF) instance for a customer. The engineer wants to enable OSPFv2 within the VRF and ensure that OSPF routes are installed in the VRF's routing table. Which command is required to start the OSPF process for the VRF?

A.router ospf 1 vrf CUSTOMER
B.ip router ospf 1 vrf CUSTOMER
C.router ospf 1 address-family ipv4 vrf CUSTOMER
D.router ospf 1 vrf CUSTOMER
AnswerA

The command 'router ospf 1 vrf CUSTOMER' starts an OSPF process with process ID 1 and associates it with the VRF named CUSTOMER. This is the correct syntax to enable OSPF within a specific VRF on Cisco IOS-XE. Once configured, OSPF will run in the context of that VRF, and routes will be installed in the VRF's routing table.

Why this answer

The correct command to enable OSPFv2 in a VRF on Cisco IOS-XE is 'router ospf <process-id> vrf <vrf-name>'. This associates the OSPF process with the specified VRF, allowing it to run in that VRF's routing context. The other options either use incorrect syntax or are appropriate for different platforms or protocols.

Exam trap

The trap here is mixing up IOS-XE and NX-OS syntax, or incorrectly placing the VRF parameter on a separate line instead of on the router ospf command itself.

21
MCQhard

A network architect is designing a Cisco SD-Access fabric. The requirement is to provide segmentation for different user groups (employees, guests, contractors) while allowing them to share the same physical infrastructure. Which Cisco SD-Access component is responsible for enforcing group-based policies between endpoints?

A.Identity Services Engine (ISE)
B.Fabric Edge Node
C.Control Plane Node (CP Node)
D.Fabric Border Node
AnswerB

Fabric edge nodes are responsible for enforcing group-based policies using Scalable Group ACLs (SGACLs). They encapsulate traffic with VXLAN and include the source group tag (SGT) and destination group tag (DGT) in the VXLAN header. Based on these tags, the edge node applies the appropriate SGACL. This enforces segmentation between user groups even when they share the same physical network.

Why this answer

In Cisco SD-Access, segmentation is achieved through the use of Scalable Group Tags (SGTs) and SGACLs. The fabric edge nodes are the enforcement points where SGACLs are applied. When an endpoint sends traffic, the edge node adds the source SGT to the VXLAN header.

The destination edge node uses the source and destination SGTs to apply the correct SGACL. This allows different user groups to be segmented even when using the same physical infrastructure. ISE assigns SGTs, but enforcement is at the edge.

Exam trap

The trap here is assuming that ISE enforces the policies because it assigns SGTs, when in fact the fabric edge nodes are the enforcement points.

22
MCQmedium

A network engineer is troubleshooting a Cisco Nexus 9000 switch configured with VXLAN EVPN. The engineer notices that the switch is not advertising EVPN routes for a specific VNI. The NVE interface is up, and the VNI is configured. Which action should the engineer take to verify that the VNI is properly associated with the EVPN control plane?

A.Check the output of 'show bgp l2vpn evpn' to see if the VNI is advertised in the EVPN address family.
B.Check the output of 'show vlan id 10' to see if VLAN 10 is active and mapped to the VNI.
C.Check the output of 'show interface nve1' to verify that the NVE interface is operational.
D.Check the output of 'show nve vni' to see if the VNI is up and associated with the NVE interface.
AnswerA

The 'show bgp l2vpn evpn' command displays the EVPN routes in the BGP table, including Type-2 and Type-3 routes for MAC and IMET. By checking this output, the engineer can verify whether the VNI is being advertised. If the VNI is not present, it indicates a configuration issue with the EVPN control plane, such as missing VNI configuration under the EVPN address family or BGP neighbor issues.

Why this answer

To verify that a VNI is properly associated with the EVPN control plane, the engineer should check the BGP EVPN table using 'show bgp l2vpn evpn'. This command displays EVPN routes, including those for the VNI. If the VNI is not advertised, it indicates a configuration issue in the EVPN address family or BGP.

Other commands like 'show nve vni' or 'show interface nve1' do not directly show EVPN route advertisement.

Exam trap

The trap here is focusing on NVE interface or VNI status commands, which show data plane information, rather than checking the BGP EVPN table, which is the control plane for EVPN route advertisement.

23
Multi-Selecthard

A network administrator is deploying Cisco ACI in a data center. The administrator must configure a bridge domain that allows Layer 2 connectivity between endpoints in the same tenant while also providing Layer 3 gateway services. The design requires that the bridge domain support both unicast routing and unknown unicast flooding. Which two settings must be enabled on the bridge domain to meet these requirements? (Choose two.)

Select 2 answers
A.Enable unicast routing on the bridge domain.
B.Enable DHCP relay on the bridge domain.
C.Enable IGMP snooping on the bridge domain.
D.Enable ARP flooding on the bridge domain.
E.Enable unknown unicast flooding on the bridge domain.
AnswersA, E

Enabling unicast routing on the bridge domain allows the ACI fabric to perform Layer 3 routing between subnets within the bridge domain and to external networks. This is required for the Layer 3 gateway services specified in the scenario, as the bridge domain acts as the default gateway for endpoints.

Why this answer

To provide Layer 3 gateway services, the bridge domain must have unicast routing enabled so it can route between subnets. To support unknown unicast flooding, the bridge domain must have unknown unicast flooding enabled. These two settings directly address the scenario's requirements, while other features like ARP flooding, IGMP snooping, and DHCP relay serve different purposes.

Exam trap

The trap here is assuming that ARP flooding is required for Layer 3 gateway services, when in fact unicast routing is the key setting, and confusing unknown unicast flooding with other flooding types.

24
MCQhard

A network engineer is configuring a Cisco Nexus 9000 switch in VXLAN EVPN mode. The engineer wants the leaf switch to advertise the local MAC addresses and IP addresses of hosts in a VLAN to remote leaf switches so that Layer 2 and Layer 3 forwarding can occur without flooding. Which EVPN route type must the engineer ensure is advertised for this purpose?

A.Type 2 MAC/IP Advertisement route
B.Type 3 Inclusive Multicast Ethernet Tag route
C.Type 1 Ethernet Auto-Discovery route
D.Type 5 IP Prefix route
AnswerA

Type 2 MAC/IP Advertisement routes carry the host MAC address and optionally the host IP address, along with the originating VTEP, for a given VNI. Advertising Type 2 routes lets remote leaf switches install MAC and ARP/ND entries and forward unicast traffic directly, avoiding flooding for known hosts.

Why this answer

EVPN Type 2 MAC/IP Advertisement routes are the route type that carries host MAC addresses and, optionally, host IP addresses with the originating VTEP. Advertising them lets remote leaf switches program MAC and ARP/ND entries for known hosts, enabling unicast forwarding without flooding. Type 1, Type 3, and Type 5 routes serve different purposes and do not carry host reachability.

Exam trap

The trap here is confusing the multicast tunnel endpoint advertisement with the host reachability advertisement, since both are exchanged automatically in a VXLAN EVPN fabric.

25
MCQeasy

A network engineer is configuring a Cisco IOS-XE router to support virtual routing and forwarding (VRF) for a multi-tenant environment. The engineer wants to ensure that traffic from each tenant is isolated and that overlapping IP addresses can be used. Which command is used to create a VRF instance and enter VRF configuration mode?

A.vrf forwarding TENANT_A
B.vrf definition TENANT_A
C.ip vrf forwarding TENANT_A
D.ip vrf TENANT_A
AnswerB

The global configuration command 'vrf definition TENANT_A' creates a VRF instance named TENANT_A and enters VRF configuration mode. This command is used on Cisco IOS-XE routers to define a VRF, which provides separate routing and forwarding tables for each tenant. Within VRF configuration mode, the engineer can configure route distinguishers (RD) and route targets (RT) to control route import and export. This command is essential for enabling VRF-lite or MPLS Layer 3 VPNs, allowing overlapping IP addresses across tenants.

Why this answer

The correct command to create a VRF instance on a Cisco IOS-XE router is 'vrf definition TENANT_A'. This command creates the VRF and enters VRF configuration mode, where route distinguishers and route targets can be configured. The 'ip vrf' command is legacy and not recommended on IOS-XE.

The 'vrf forwarding' and 'ip vrf forwarding' commands are used on interfaces to assign them to an existing VRF, not to create one.

Exam trap

The trap here is confusing the legacy 'ip vrf' command with the modern 'vrf definition' command, as both create VRFs but only the latter is recommended on IOS-XE.

26
MCQmedium

A network engineer deploys Cisco HyperFlex with ESXi hosts and a vSwitch. The requirement is that storage traffic for the HyperFlex distributed data platform be isolated from management and VM traffic, and that jumbo frames be used end to end. Which configuration on the ESXi host satisfies this requirement?

A.Create a VMkernel adapter on the VM traffic vSwitch with an MTU of 1500 and tag it with the storage VLAN.
B.Add the storage VMkernel adapter to the existing management vSwitch and set the MTU to 9000 on that vSwitch.
C.Create a dedicated vSwitch with an MTU of 9000, attach the storage VMkernel adapter to it, and place the physical uplinks connected to the storage VLAN on that vSwitch.
D.Configure a distributed vSwitch with an MTU of 9000 and attach all VMkernel adapters, including storage, to a single uplink team.
AnswerC

Isolating storage on its own vSwitch with a 9000 MTU and dedicated uplinks on the storage VLAN separates the traffic from management and VM flows while enabling jumbo frames end to end. The storage VMkernel adapter carries the HyperFlex data traffic, and the dedicated uplinks ensure the storage VLAN is not shared with other traffic types. This matches HyperFlex networking requirements.

Why this answer

HyperFlex storage traffic should run on a dedicated vSwitch with jumbo frames enabled and its own physical uplinks on the storage VLAN. This isolates the distributed data platform traffic from management and VM flows and allows the 9000 MTU to be applied end to end. Sharing a vSwitch, using a 1500 MTU, or merging storage into a common uplink team all fail the isolation and jumbo frame requirements.

Exam trap

The trap here is assuming that simply raising the MTU to 9000 satisfies the design, when dedicated storage vSwitch and uplink isolation are equally required.

27
MCQeasy

A network administrator is configuring a Cisco CSR 1000v router in a virtualized environment. The administrator needs to ensure that the virtual router can forward traffic between virtual machines on different VLANs. Which feature must be enabled on the CSR 1000v to support this?

A.VRF Lite
B.IPsec VPN
C.IP routing
D.NAT
AnswerC

Enabling IP routing on the Cisco CSR 1000v allows it to route traffic between different VLANs. By default, routing may be disabled. Once enabled with the 'ip routing' command, the router can forward packets between subnets, including those on different VLANs, provided interfaces are configured correctly.

Why this answer

To forward traffic between different VLANs, a Cisco CSR 1000v must have IP routing enabled. This allows the router to route packets between subnets configured on different interfaces or subinterfaces. Without IP routing, the router will not forward traffic between VLANs, regardless of other features.

Exam trap

The trap here is confusing features that provide security or isolation, such as VRF Lite or IPsec, with the fundamental requirement of enabling IP routing for basic inter-VLAN communication.

28
MCQhard

An engineer configures VXLAN EVPN on a Nexus 9000 switch. The configuration is shown. The switch does not advertise any EVPN routes for VNI 10100. Which configuration change is required to fix this issue?

A.Configure "evpn" and "vni 10100 l2" under the BGP address-family l2vpn evpn.
B.Remove the mcast-group from the NVE member, because EVPN uses BGP for control plane.
C.Change the source-interface to a physical interface.
D.Add an IP address to the VLAN 100 interface in the default VRF.
AnswerA

The VNI must be explicitly activated under BGP EVPN. Without the 'vni 10100 l2' configuration inside address-family l2vpn evpn, BGP has no awareness of this L2 VNI and will not originate or import the type-2 (MAC/IP) and type-3 (inclusive multicast) routes needed for remote VTEPs to learn MAC addresses. Adding that command, along with 'evpn' as the address family, is what makes the control plane advertise the VNI. This is the missing configuration causing the issue.

Why this answer

For VXLAN EVPN on a Nexus 9000, the BGP address-family l2vpn evpn must explicitly contain the 'evpn' keyword and the 'vni 10100 l2' command to advertise Layer 2 VNI routes. Without this configuration, BGP does not know to inject the VNI's MAC/VTEP information into the EVPN route table, so no EVPN routes are advertised for VNI 10100.

Exam trap

Cisco often tests the distinction between the NVE interface configuration (which enables VXLAN encapsulation) and the BGP EVPN address-family configuration (which enables route advertisement), leading candidates to mistakenly focus on NVE or interface settings instead of the missing BGP VNI injection.

How to eliminate wrong answers

Option B is wrong because removing the mcast-group from the NVE member would break BUM traffic replication in multicast mode, but the issue is about EVPN route advertisement, not data-plane flooding; EVPN uses BGP for control plane, but the mcast-group is still needed for multicast-based BUM traffic. Option C is wrong because changing the source-interface to a physical interface is not required; a loopback interface is the recommended source for NVE to ensure stability and is not the cause of missing EVPN routes. Option D is wrong because adding an IP address to VLAN 100 interface in the default VRF is unrelated to EVPN route advertisement; VLAN 100 is the Layer 2 VLAN associated with VNI 10100, but its SVI IP is only needed for Layer 3 VNI or gateway functionality, not for advertising EVPN routes.

29
MCQmedium

A network engineer is configuring a Cisco Nexus 9000 switch as a VTEP in a VXLAN EVPN fabric. The engineer wants to ensure that the switch uses the loopback0 interface as the source for VXLAN tunnels and that it can dynamically learn remote VTEPs via BGP EVPN. Which command set is required under the NVE interface?

A.interface nve1; source-interface loopback0; vni 10000; ip address 10.0.0.1/32
B.interface nve1; source-interface loopback0; no shutdown
C.interface nve1; source-interface loopback0; peer-ip 10.0.0.2
D.interface nve1; source-interface loopback0; host-reachability protocol bgp
AnswerD

Under the NVE interface, source-interface loopback0 sets the VTEP IP address, and host-reachability protocol bgp enables BGP EVPN for remote VTEP and MAC learning. This combination is essential for a functioning VTEP in an EVPN fabric. Without the source-interface, the NVE would not know which IP to use for tunnels, and without host-reachability, it would rely on data-plane learning.

Why this answer

For a Cisco Nexus 9000 VTEP in an EVPN fabric, the NVE interface must be configured with source-interface loopback0 to set the tunnel source IP and host-reachability protocol bgp to enable dynamic learning of remote VTEPs and MAC addresses via BGP EVPN. Other commands like no shutdown are necessary but insufficient, and static peer-ip or IP address under NVE is incorrect.

Exam trap

The trap here is forgetting the host-reachability protocol bgp command, which is often overlooked when focusing only on the source-interface configuration.

30
MCQeasy

A network engineer is configuring a Cisco Catalyst 9000 switch to support a virtual routing and forwarding (VRF) instance for a guest network. The engineer wants to ensure that traffic from the guest VRF cannot leak into the corporate VRF. Which configuration step is required to maintain isolation between VRFs?

A.Assign the guest VRF to a separate VLAN and configure inter-VLAN routing.
B.Configure a route target export and import policy to control route leaking.
C.Place the guest network interfaces into the guest VRF and do not configure any route leaking.
D.Enable VRF-aware routing and ensure no static routes point between VRFs.
AnswerC

VRF instances are isolated by default. By assigning interfaces to the guest VRF, traffic within that VRF is separate from the corporate VRF. As long as no route leaking (such as static routes or BGP route targets) is configured, the VRFs remain isolated. This is the correct and sufficient step to maintain isolation.

Why this answer

VRFs provide logical separation of routing tables. When you assign interfaces to a VRF, those interfaces use that VRF's routing table. By default, there is no communication between VRFs unless you explicitly configure route leaking, such as static routes with next-hop VRF or BGP route targets.

Therefore, placing the guest interfaces in the guest VRF and not configuring any route leaking ensures isolation. Other options either do not enforce isolation or are unnecessary.

Exam trap

The trap here is overcomplicating VRF isolation by thinking that route targets or inter-VLAN routing are needed, when simply placing interfaces in the VRF without route leaking is sufficient.

31
MCQmedium

A network engineer is deploying a Cisco Catalyst 9300 switch stack that will host several isolated tenant environments. Each tenant must have its own separate routing table and its own independent instance of a dynamic routing protocol on the same physical switch, while sharing the same physical uplinks to the core. Which technology should the engineer implement to meet these requirements?

A.Virtual Routing and Forwarding (VRF)
B.Virtual Switching System (VSS)
C.Private VLAN (PVLAN) configuration
D.VLAN access map on the uplink
AnswerA

VRF creates multiple independent Layer 3 routing and forwarding tables on a single physical device, so each tenant gets its own RIB/FIB and can run a separate routing protocol instance. This directly satisfies the requirement of isolated routing tables plus independent protocol instances sharing the same physical uplinks and hardware.

Why this answer

VRF is the Cisco IOS/IOS-XE feature that partitions a single physical router or switch into multiple logically separate Layer 3 routing domains. Each VRF maintains its own routing and forwarding table and can run its own routing protocol process, which is exactly what is needed when several tenants must share hardware and uplinks while remaining logically isolated.

Exam trap

The trap here is confusing Layer 2 isolation features such as private VLANs with true Layer 3 routing table separation.

32
MCQeasy

A network engineer is deploying a virtualized branch solution using Cisco Enterprise Network Function Virtualization Infrastructure Software (NFVIS). The goal is to run multiple virtual network functions such as a virtual router and a virtual firewall on a single Cisco UCS E-Series or C-Series server at the branch. Which statement accurately describes how NFVIS supports this deployment?

A.NFVIS provides a hypervisor and lifecycle management for hosting multiple VNFs on the branch server
B.NFVIS replaces the need for any hypervisor by running VNFs directly on bare metal without virtualization
C.NFVIS only supports a single VNF per physical server and cannot host multiple virtual machines
D.NFVIS is a cloud-only orchestration tool that cannot run on branch appliances
AnswerA

Cisco NFVIS is a Linux KVM-based virtualization platform that provides the hypervisor, VM lifecycle management, and orchestration APIs needed to host multiple virtual network functions on a single branch server. It allows the engineer to deploy, monitor, and manage VNFs such as virtual routers and firewalls from a centralized interface, directly supporting the multi-VNF branch design in the scenario.

Why this answer

Cisco NFVIS is a KVM-based virtualization platform that supplies the hypervisor, VM lifecycle management, and orchestration needed to run multiple virtual network functions on a single branch server. This enables consolidating a virtual router, virtual firewall, and other services at the branch, which matches the engineer's deployment goal.

Exam trap

The trap here is assuming NFVIS is only an orchestration overlay or that it removes the hypervisor, when it actually embeds a KVM hypervisor to host multiple VNFs.

33
MCQhard

A network administrator is deploying Cisco ACI in a data center. The administrator needs to ensure that a new tenant's application profile can communicate with an external Layer 2 network that is connected to a border leaf switch. Which ACI construct must be configured to extend the tenant's bridge domain to the external network?

A.A Layer 3 Outside (L3Out)
B.A VXLAN tunnel to the external switch
C.A Layer 2 Outside (L2Out)
D.A bridge domain with a flood scope of 'external'
AnswerC

In Cisco ACI, an L2Out is used to extend a bridge domain to an external Layer 2 network. It is configured on a border leaf and includes an external bridged domain and an external bridged network. This allows Layer 2 connectivity between the ACI fabric and external devices, which is exactly what is needed to extend the tenant's bridge domain.

Why this answer

To extend a Cisco ACI bridge domain to an external Layer 2 network, an L2Out must be configured. This construct defines the external bridged domain and network, and is applied to a border leaf interface. It allows Layer 2 traffic to pass between the ACI fabric and external devices, preserving VLAN tags or mapping them as needed.

Exam trap

The trap here is confusing L2Out with L3Out; L3Out is for routed connectivity, while L2Out is specifically for Layer 2 extension.

34
MCQeasy

A network engineer is configuring a Cisco Nexus 9000 switch as a VXLAN Tunnel Endpoint. The engineer needs to define the source interface used for the VXLAN tunnels and map VLANs to a VNI. Which command sequence accomplishes this?

A.interface nve1, then source-interface loopback1, then member vni 10000 associated-vrf tenant1
B.interface nve1, then source-interface loopback1, then member vni 10000, then vlan 100 under the VNI
C.feature nv overlay, interface nve1, source-interface loopback1, member vni 10000, then under interface Vlan100 configure vn-segment 10000
D.interface vxlan1, then source-interface loopback1, then vni 10000 vlan 100 mapping
AnswerC

This sequence enables the NV overlay feature, creates the NVE interface, sets the loopback as the tunnel source, adds the VNI as a member, and maps VLAN 100 to VNI 10000 using vn-segment under the SVI. This is the correct Nexus 9000 method for defining a VTEP and binding a VLAN to a VNI for Layer 2 VXLAN bridging. All required elements are present and correctly placed.

Why this answer

On Nexus 9000 NX-OS, VXLAN configuration requires enabling the NV overlay feature, creating interface nve1, specifying the loopback as the tunnel source, adding the VNI as a member, and mapping the VLAN to the VNI with vn-segment under the VLAN interface. The other options misplace commands or use syntax from other platforms.

Exam trap

The trap here is mixing up the placement of the VLAN-to-VNI mapping, which belongs under the VLAN interface as vn-segment, not under the NVE interface or the VNI member configuration.

35
MCQhard

A network architect is designing a Cisco SD-Access fabric. The requirement is to provide secure segmentation for different departments without deploying separate physical networks or traditional VRFs on every switch. Which Cisco SD-Access component provides this segmentation by using a group-based policy model?

A.Access Control List (ACL)
B.Scalable Group Tag (SGT)
C.VLAN pool
D.Virtual Routing and Forwarding (VRF)
AnswerB

SGTs are used in Cisco SD-Access to provide micro-segmentation. Each endpoint is assigned an SGT, and group-based policies (SGACLs) enforce traffic between groups. This allows segmentation without traditional VRFs on every switch, meeting the requirement for secure departmental separation.

Why this answer

Cisco SD-Access uses Scalable Group Tags (SGTs) to implement group-based segmentation. Endpoints are assigned SGTs, and Security Group ACLs (SGACLs) enforce policy between groups. This approach provides micro-segmentation without the need for traditional VRFs on every switch, simplifying operations and improving security.

Exam trap

The trap here is assuming that VRFs are the only way to segment traffic, overlooking the identity-based, group-policy model that SD-Access provides through SGTs.

36
Multi-Selectmedium

A network engineer is deploying VXLAN EVPN on a Cisco Nexus 9000 switch. Which two statements about the configuration of the NVE interface are true? (Choose two.)

Select 2 answers
A.The NVE interface is a physical interface that connects to the underlay network.
B.The NVE interface requires an IP address to be configured directly on it.
C.The NVE interface can be configured with multiple source interfaces for redundancy.
D.The NVE interface must be configured with a source interface that is reachable via the underlay network.
E.Each VNI must be associated with the NVE interface using the member vni command.
AnswersD, E

The source interface for the NVE interface must be reachable via the underlay network so that VXLAN tunnels can be established. Typically, a loopback interface is used, and its IP address must be advertised into the underlay routing protocol. Without reachability, VXLAN traffic cannot be encapsulated and forwarded to remote VTEPs.

Why this answer

The two true statements are that the NVE interface must have a source interface reachable via the underlay network, and each VNI must be associated with the NVE interface using the member vni command. These are essential for VXLAN operation. The source interface provides the VTEP IP, and the VNI association enables VXLAN encapsulation for specific VNIs.

Exam trap

The trap here is assuming that the NVE interface is a physical interface or that it requires an IP address directly, when in fact it is a logical interface that relies on a separate source interface.

37
MCQmedium

A network engineer is configuring VXLAN on a Cisco Nexus 9000 switch. The engineer wants to ensure that the VXLAN tunnel interface uses the loopback 0 interface as the source for all VXLAN traffic. Which command should be entered under the NVE interface configuration?

A.tunnel source loopback0
B.source-interface loopback0
C.vxlan source-interface loopback0
D.interface loopback0
AnswerB

This command correctly specifies the loopback 0 interface as the source for VXLAN tunnel traffic. It ensures that the VTEP IP address is derived from a stable, always-up interface, which is a best practice for VXLAN deployments. The loopback interface provides redundancy and avoids disruption if a physical interface goes down.

Why this answer

The correct command to set the source interface for VXLAN tunnels under the NVE interface is 'source-interface loopback0'. This ensures that the VTEP IP address is derived from a stable loopback interface, which is a best practice for VXLAN deployments. The other options are either invalid or apply to different technologies.

Exam trap

The trap here is confusing the command syntax for VXLAN with that of traditional GRE tunnels, leading to the use of 'tunnel source' instead of the correct 'source-interface'.

38
MCQhard

An engineer is configuring a Cisco Nexus 9000 switch running VXLAN EVPN. Tenant traffic must be encapsulated with a VXLAN header that includes a 24-bit VNI, and the underlay must provide loopback-based VTEP addressing with ECMP. The engineer notices that the switch is not forming VXLAN tunnels to remote leaf switches. Which configuration issue is the most likely cause?

A.The switch is using a 12-bit VLAN ID instead of the required 24-bit VNI in the VXLAN header
B.The NVE interface is missing the source-interface loopback and the VNI-to-VLAN mapping is incomplete
C.The underlay is running OSPF instead of BGP, which prevents VXLAN tunnel establishment
D.The switch is configured with VXLAN VNI 16777216, which exceeds the 24-bit range
AnswerB

The NVE interface requires a source-interface, typically a loopback, to establish the VTEP address used in VXLAN tunnels. If the source interface is missing or the VNI-to-VLAN mapping under the NVE interface is incomplete, the switch cannot build tunnels or map traffic into VNIs. This directly explains why VXLAN tunnels to remote leaf switches are not forming in the scenario.

Why this answer

VXLAN tunnel formation on a Nexus 9000 requires the NVE interface to have a source-interface, usually a loopback, and correct VNI-to-VLAN mappings. Without a valid VTEP source address or with incomplete VNI mappings, the switch cannot establish tunnels to remote leaf VTEPs, which matches the observed failure.

Exam trap

The trap here is blaming the underlay routing protocol or VNI bit width, when the actual prerequisite for tunnel formation is a valid NVE source interface and complete VNI-to-VLAN mappings.

39
MCQhard

A network engineer is troubleshooting a Cisco IOS-XE router that hosts several virtual routing and forwarding instances. A route to 10.20.30.0/24 exists in both the global routing table and in VRF CUSTOMER_A. A packet arrives on an interface assigned to VRF CUSTOMER_A with destination 10.20.30.10. How does the router determine which routing table to consult?

A.It always consults the global routing table first and falls back to the VRF table only if no match is found.
B.It uses the destination address to choose the VRF whose route has the longest prefix match.
C.It uses the VRF forwarding table associated with the ingress interface's VRF.
D.It compares administrative distance between the global and VRF entries and selects the lower value.
AnswerC

VRF selection is driven by the ingress interface. Because the receiving interface is bound to VRF CUSTOMER_A, the router performs the lookup in the CUSTOMER_A forwarding table, where the 10.20.30.0/24 route may point to a different next hop than the global entry, keeping tenant traffic isolated.

Why this answer

The VRF used for a forwarding lookup is determined by the VRF membership of the ingress interface, not by the destination address. Once the interface's VRF is identified, the router performs a longest prefix match inside that VRF's forwarding table, which keeps overlapping tenant and global addressing independent and isolated.

Exam trap

The trap here is believing the router compares or falls back between the global table and a VRF table when both contain the same prefix.

40
MCQmedium

A network engineer is configuring a VRF on a Cisco IOS-XE router to isolate a customer's traffic. The engineer creates VRF CUST_A, assigns the customer-facing interface to it, and runs the show ip route vrf CUST_A command, which returns no routes. The interface is up and the customer router is reachable. What is the most likely cause?

A.The ip vrf forwarding command must be applied to the VRF definition rather than to the interface.
B.The VRF was created but no route distinguisher or route target was configured, which is required for any VRF to install routes.
C.The global routing table must be cleared with the clear ip route * command before VRF routes will appear.
D.The interface was placed in the VRF, but no IP address or routing protocol was configured on that interface within the VRF.
AnswerD

An interface assigned to a VRF contributes its connected route to that VRF's table only if it has an IP address. If the interface has no address, or if no static route or routing protocol is configured inside the VRF address family, the VRF routing table will be empty. This matches the symptom of show ip route vrf CUST_A returning no routes.

Why this answer

A VRF routing table is populated by connected routes from interfaces that both belong to the VRF and have IP addresses, plus any static routes or dynamic routing configured inside the VRF address family. If the interface was moved into the VRF but never addressed, or if no routing protocol or static route was configured within the VRF, the table stays empty. Verifying the interface address and the VRF's routing configuration explains the symptom.

Exam trap

The trap here is assuming a VRF needs a route distinguisher and route target to hold local routes, when those are only needed for MPLS L3VPN signaling.

41
MCQmedium

A network engineer is configuring a Cisco Nexus 9000 switch as a VXLAN Tunnel Endpoint (VTEP). The switch has two loopback interfaces: Loopback0 (10.0.0.1/32) and Loopback1 (10.0.0.2/32). The engineer wants VXLAN traffic to use the loopback interface that is also used for BGP EVPN peering. Which command should be used to specify the source interface for the VXLAN tunnels?

A.interface nve1 source-interface loopback1
B.interface loopback1 vxlan source-interface
C.interface nve1 source-interface loopback0
D.feature nv overlay source-interface loopback1
AnswerA

The 'source-interface loopback1' command under the NVE interface configuration sets Loopback1 as the source for all VXLAN encapsulated traffic. Since Loopback1 is also used for BGP EVPN peering, this ensures consistent reachability and avoids asymmetric routing. This is the correct way to bind the VTEP source to a specific loopback, which is a common best practice in VXLAN EVPN deployments.

Why this answer

The correct configuration is to specify the source interface under the NVE interface using 'source-interface loopback1'. This binds the VTEP to the same loopback used for BGP EVPN peering, ensuring that the tunnel source address is reachable and consistent with the control plane. Using a different loopback could cause routing inconsistencies and is not recommended when the same loopback is already used for EVPN peering.

Exam trap

The trap here is confusing the global 'feature nv overlay' command with the interface-level source-interface configuration, or assuming the source interface should be configured on the loopback rather than under the NVE interface.

42
MCQeasy

A network administrator is configuring a Cisco IOS-XE router to support Virtual Routing and Forwarding (VRF). The administrator wants to ensure that traffic from different VRFs can be routed between each other using a shared service VRF. Which VRF feature allows routes to be leaked between VRFs?

A.VRF forwarding table
B.IP routing protocol redistribution
C.Route distinguisher
D.Route target export and import
AnswerD

In VRF-lite or MPLS L3VPN, route targets control the import and export of routes between VRFs. By configuring matching route targets on two VRFs, routes from one VRF can be imported into another. This is the standard method for route leaking between VRFs. It allows controlled communication between VRFs without merging them entirely.

Why this answer

Route targets are used to control the import and export of routes between VRFs. By configuring matching route targets on two VRFs, routes can be leaked from one VRF to another. This is the standard method for inter-VRF communication in MPLS L3VPN and VRF-lite environments.

Route distinguishers make prefixes unique but do not control leaking.

Exam trap

The trap here is confusing the role of the route distinguisher with that of the route target; the RD makes prefixes unique, while the RT controls import/export.

43
MCQmedium

A network engineer is configuring NTP authentication on a Cisco IOS-XE router. The goal is to ensure the router only synchronizes with a trusted NTP server and that the server's keys are validated. Which sequence of configuration steps correctly enforces authenticated NTP peering?

A.Define the key with `ntp authentication-key 1 md5 <key>` and add `ntp server <ip> key 1`, omitting `ntp authenticate` because the server command implies authentication.
B.Enable `ntp authenticate` and mark the key trusted with `ntp trusted-key 1`, but do not configure the key value itself, relying on the server to supply it.
C.Configure `ntp master 1` on the router and add `ntp server <ip>`, because a stratum 1 master enforces authentication automatically.
D.Enable `ntp authenticate`, define the key with `ntp authentication-key 1 md5 <key>`, mark it trusted with `ntp trusted-key 1`, then add `ntp server <ip> key 1`.
AnswerD

This sequence turns on authentication globally, creates the MD5 key, marks that key as trusted so the router accepts it, and associates the key with the server. Each step is required: without `ntp authenticate` the router ignores authentication, without a trusted key it rejects valid packets, and without the key number on the server command it will not use the key for that peer. Together they enforce authenticated peering.

Why this answer

Enforcing authenticated NTP requires four coordinated elements: the global `ntp authenticate` command, a defined authentication key with its MD5 value, a `ntp trusted-key` statement for that key number, and the key reference on the `ntp server` command. Missing any one element breaks the chain, either by leaving authentication disabled, by rejecting valid packets, or by failing to associate the key with the specific peer.

Exam trap

The trap here is thinking that referencing a key on the `ntp server` command is sufficient, when the global `ntp authenticate` command and a trusted-key statement are also mandatory.

44
MCQhard

A network engineer configured VRF TENANT_A and moved the subinterfaces into the VRF. After the change, the CEF table shows the prefixes but the next-hop addresses are unreachable. What is the most likely cause?

A.LISP is not configured to map the virtual network.
B.The next-hop IP addresses are in the global routing table, not in the VRF.
C.OSPF is not redistributing the routes into the VRF.
D.The physical interface is not configured as a trunk.
AnswerB

VRF segregation creates an independent routing and CEF table, so next hops must reside within the same VRF. If the next-hop addresses belong to the global table, they are unresolvable inside VRF TENANT_A, leaving prefixes present but next hops unreachable.

Why this answer

When subinterfaces are moved into a VRF, the CEF table for that VRF will contain the learned prefixes, but the next-hop addresses must also be reachable within the same VRF. If the next-hop IP addresses reside in the global routing table instead of the VRF, the VRF will have no route to those next hops, causing them to be marked as unreachable. This is a common misconfiguration where the next-hop adjacency is not established within the VRF context.

Exam trap

Cisco often tests the concept that VRF creates a completely isolated routing table, and the trap here is that candidates assume CEF showing the prefix means the route is fully functional, overlooking that the next-hop must also be in the same VRF.

How to eliminate wrong answers

Option A is wrong because LISP (Locator/ID Separation Protocol) is not required for basic VRF operation; it is used for overlay network virtualization and mobility, not for resolving next-hop reachability within a VRF. Option C is wrong because OSPF redistribution is not the root cause; the issue is that the next-hop addresses are not present in the VRF's routing table, not that routes are missing from OSPF. Option D is wrong because trunk configuration on the physical interface is irrelevant to VRF next-hop reachability; subinterfaces can be placed into a VRF regardless of whether the parent interface is a trunk or access port.

45
MCQhard

A network architect is designing a Cisco ACI fabric for a multi-tenant data center. Tenants must be isolated at Layer 3, but some tenants require shared services such as a firewall and load balancer. Which Cisco ACI construct should the architect use to allow selective communication between tenants while maintaining isolation?

A.A VRF leak between the tenant VRFs using route targets
B.A bridge domain shared between tenants with a common subnet
C.A shared L3Out with a common EPG for all tenants
D.A contract between the tenant EPG and a shared services EPG in the common tenant
AnswerD

In Cisco ACI, the common tenant can host shared services EPGs, and contracts can be exported and consumed across tenants. This allows a tenant EPG to communicate with the shared firewall or load balancer while keeping other inter-tenant traffic isolated. The contract defines exactly which protocols and ports are permitted, satisfying both sharing and isolation.

Why this answer

Cisco ACI enables selective inter-tenant communication by placing shared services in the common tenant and using contracts that are exported and consumed by tenant EPGs. This preserves Layer 3 isolation between tenants while permitting only the traffic defined by the contract. The shared services EPG can be a firewall or load balancer, and the contract enforces the allowed protocols and ports.

Exam trap

The trap here is thinking that shared services require merging VRFs or bridge domains, when ACI actually provides cross-tenant contracts with the common tenant to maintain isolation.

46
MCQmedium

A network engineer is deploying a VXLAN EVPN fabric on Cisco Nexus 9000 switches. The underlay is a Layer 3 routed fabric using OSPF. The engineer needs to ensure that multicast replication is not used for BUM (Broadcast, Unknown Unicast, Multicast) traffic. Which VXLAN EVPN configuration is required on the leaf switches?

A.Configure the NVE interface with a multicast group address using the `member vni <vni> mcast-group <group-address>` command.
B.Configure PIM sparse mode on all underlay interfaces and enable multicast routing on the leaf switches.
C.Configure the NVE interface with `ingress-replication protocol bgp` and ensure EVPN is enabled for the VNI.
D.Configure the NVE interface with `source-interface loopback0` and rely on OSPF to flood BUM traffic to all VTEPs.
AnswerC

Ingress replication with BGP EVPN allows the leaf to replicate BUM traffic to all remote VTEPs in the EVPN control plane without using multicast in the underlay. This is the correct approach when multicast replication is not desired. The command `ingress-replication protocol bgp` enables this behavior.

Why this answer

To avoid multicast replication in a VXLAN EVPN fabric, ingress replication must be used. The leaf switches must be configured with `ingress-replication protocol bgp` under the NVE interface, and EVPN must be enabled for the VNI. This allows the leaf to use the EVPN control plane to discover remote VTEPs and replicate BUM traffic to them via unicast.

Multicast replication requires PIM in the underlay, which is not desired here.

Exam trap

The trap here is assuming that VXLAN always requires multicast in the underlay for BUM traffic replication, when in fact ingress replication via BGP EVPN is a common alternative.

47
MCQhard

A network engineer is troubleshooting a Cisco ACI environment where a tenant's application is experiencing intermittent connectivity issues. The engineer suspects that the issue is related to the ACI fabric's forwarding behavior. Which tool can be used to verify the end-to-end path and policy enforcement for a specific flow within the ACI fabric?

A.Cisco APIC Tenant Traceroute
B.Cisco APIC Contract Viewer
C.Cisco ACI Virtual Edge (AVE) CLI
D.Cisco Nexus Dashboard Insights
AnswerA

The Cisco APIC Tenant Traceroute tool allows engineers to trace the path of a specific flow through the ACI fabric, from source to destination. It simulates the flow and shows each step, including policy enforcement points, leaf and spine switches, and any drop or redirect actions. This is ideal for troubleshooting intermittent connectivity issues because it provides visibility into the actual forwarding path and policy application. It helps identify where packets may be dropped or misrouted within the fabric.

Why this answer

The Cisco APIC Tenant Traceroute tool is designed to trace the end-to-end path of a specific flow within the ACI fabric. It simulates the flow and shows each hop, including policy enforcement and any drops. This makes it the best choice for troubleshooting intermittent connectivity issues.

The Contract Viewer only shows policy configuration, the AVE CLI is limited to virtual edge troubleshooting, and Nexus Dashboard Insights is more for analytics than on-demand path tracing.

Exam trap

The trap here is assuming that a monitoring tool like Nexus Dashboard Insights can provide the same real-time path tracing as the dedicated Tenant Traceroute tool.

48
MCQhard

A cloud provider uses Cisco ACI to automate provisioning of tenant networks. A new tenant requires a Layer 2 bridge domain that extends to an external Layer 2 network via a VPC. The engineer creates a bridge domain with the settings: Type: Regular, L2 Unknown Unicast: Flood, L3 Unknown Multicast Flood: Flood, and Multi-Destination Flooding: Flood. The VPC is configured as a virtual port channel. The tenant reports that broadcast traffic is not reaching the external network. What is the most likely cause?

A.The VPC configuration does not support L2 extension.
B.The bridge domain is configured as proxy mode for L2 unknown unicast.
C.The L2Out is not configured to flood BUM traffic.
D.The bridge domain type should be set to 'L2 Only'.
AnswerC

An L2Out connects the ACI fabric to an external Layer 2 network, but by default BUM (broadcast, unknown unicast, multicast) traffic is not automatically flooded through every L2Out. The 'flood on' setting under the L2Out must be explicitly enabled so that BUM frames received in the BD are also sent to the external network; without it, BUM traffic is dropped or handled only locally. Since this L2Out lacks that flood configuration, the L2 extension does not actually extend L2 flooding, which explains the connectivity problem.

Why this answer

The bridge domain is configured to flood BUM (Broadcast, Unknown Unicast, and Multicast) traffic internally, but the L2Out (Layer 2 external connection) must also be explicitly configured to flood BUM traffic to the external network. Without this configuration on the L2Out, the ACI fabric will not forward broadcast or multicast frames across the VPC to the external Layer 2 network, even though the bridge domain itself permits flooding.

Exam trap

Cisco often tests the distinction between bridge domain flood settings and L2Out flood settings, trapping candidates who assume that enabling flooding in the bridge domain automatically allows BUM traffic to reach external networks.

How to eliminate wrong answers

Option A is wrong because a VPC (Virtual Port Channel) in ACI is specifically designed to support Layer 2 extension by providing a loop-free, redundant connection to external switches, and it does not inherently block L2 traffic. Option B is wrong because the bridge domain is explicitly configured with 'L2 Unknown Unicast: Flood', not proxy mode; proxy mode would be 'L2 Unknown Unicast: Proxy', which is not the case here. Option D is wrong because the bridge domain type 'Regular' is appropriate for a Layer 2 bridge domain that extends to an external network; setting it to 'L2 Only' would disable Layer 3 forwarding but would not affect the flooding of BUM traffic to the external network via the L2Out.

49
Multi-Selectmedium

A network architect is evaluating Cisco SD-WAN to connect branch offices to data centers and public cloud workloads. The architect wants to understand which capabilities are provided by the Cisco SD-WAN solution. (Choose two.)

Select 2 answers
A.Replacement of all branch routing with static routes only
B.Elimination of all encryption on the overlay tunnels
C.Centralized policy management through vManage with templates pushed to edge devices
D.Mandatory use of MPLS as the only WAN transport
E.Application-aware routing that selects the best path based on policy and link quality
AnswersC, E

Cisco SD-WAN centralizes configuration and policy in vManage, which pushes feature templates and centralized policies to vEdge and cEdge devices. This enables consistent, scalable provisioning of thousands of branches without manual CLI configuration. It directly supports the architect's goal of managing branch-to-data-center and cloud connectivity in a unified, policy-driven manner across the overlay.

Why this answer

Cisco SD-WAN delivers application-aware routing that continuously measures path quality and steers traffic per policy, and it centralizes configuration and policy in vManage for scalable provisioning. These two capabilities align with the architect's goal of optimizing and managing branch-to-data-center and cloud connectivity across multiple transports.

Exam trap

The trap here is assuming SD-WAN forces a single transport or static-only routing, when it is actually transport-agnostic and supports dynamic routing with application-aware path selection.

50
MCQmedium

A network administrator is deploying Cisco Application Centric Infrastructure (ACI) and needs to allow two endpoint groups (EPGs) in different bridge domains to communicate while applying a contract that permits only TCP port 443. Which ACI construct provides the policy enforcement point where the contract is applied?

A.The VXLAN tunnel interface on the spine
B.The bridge domain subnet SVI on the border leaf
C.The policy enforcement point on the leaf where the EPGs reside
D.The APIC controller cluster policy compiler
AnswerC

In ACI, the leaf switch acts as the policy enforcement point, translating contracts into hardware ACL and forwarding rules applied to the EPG interfaces. When a contract permitting TCP 443 is attached between EPGs, the leaf enforces that filter for traffic between them, which is exactly the construct required.

Why this answer

ACI applies contracts at the leaf switch, which acts as the policy enforcement point for the attached EPGs. The APIC distributes the compiled policy, but the leaf hardware renders and enforces the permit for TCP port 443 between the two EPGs in their respective bridge domains.

Exam trap

The trap here is assuming the central APIC controller enforces contracts in the data path rather than only distributing policy.

51
Multi-Selectmedium

A network engineer is designing a VXLAN EVPN fabric using Cisco Nexus 9000 switches. The engineer must choose a multicast mode for BUM (Broadcast, Unknown unicast, Multicast) traffic replication. Which two statements are true regarding the use of multicast in a VXLAN EVPN fabric? (Choose two.)

Select 2 answers
A.Ingress replication is required when using multicast mode.
B.Multicast mode eliminates the need for BGP EVPN for control plane learning.
C.Each VNI is typically mapped to a unique multicast group address.
D.Multicast requires the underlay network to support PIM SM and an RP.
E.Multicast mode requires a separate multicast group for each VTEP.
AnswersC, D

In a multicast-based VXLAN fabric, each VNI is mapped to a multicast group address. VTEPs that have the VNI configured join that group via IGMP. When a VTEP needs to send BUM traffic for that VNI, it sends the VXLAN-encapsulated packet to the multicast group, and all VTEPs in the group receive it. This mapping is configured on each VTEP.

Why this answer

In a VXLAN EVPN fabric using multicast for BUM traffic, the underlay must support multicast routing, typically PIM SM with an RP. Each VNI is mapped to a unique multicast group address, and VTEPs join the group for their VNIs. This allows BUM traffic to be replicated to all VTEPs in the VNI.

BGP EVPN is still used for control plane learning.

Exam trap

The trap here is assuming multicast replaces BGP EVPN or that ingress replication is used alongside multicast, when in fact they are alternative methods for BUM traffic handling.

52
Multi-Selecteasy

Which TWO statements correctly describe characteristics of virtual device contexts (VDCs) in Cisco Nexus switches?

Select 2 answers
A.VDCs allow overlapping VLAN IDs across different VDCs only if using different VNIs.
B.VDCs provide Layer 3 routing isolation by default across all VDCs.
C.Each VDC can have its own admin account and separate management interface.
D.VDCs are supported on all Cisco IOS-XE switches.
E.VDCs enable partitioning of a single physical switch into multiple logical switches.
AnswersC, E

Correct: VDCs provide administrative and management isolation.

Why this answer

Each VDC in a Cisco Nexus switch can be configured with its own administrative credentials and a dedicated management interface (e.g., mgmt0). This allows separate administrative domains and management access per VDC, which is a key feature for multi-tenant environments.

Exam trap

Cisco often tests the misconception that VDCs automatically provide Layer 3 routing isolation, but in reality, routing isolation requires explicit VRF configuration per VDC.

53
MCQmedium

A network engineer is configuring a Cisco Nexus 9000 switch as a VTEP in a VXLAN EVPN fabric. The engineer needs to specify the loopback0 interface as the source for VXLAN tunnels. Which command must be entered under the NVE interface configuration?

A.vxlan source-interface loopback0
B.interface loopback0
C.source-interface loopback0
D.source loopback0
AnswerC

This command correctly sets the loopback0 interface as the source for VXLAN tunnels on the NVE interface. In Cisco NX-OS, under interface nve1, the 'source-interface loopback0' command designates the loopback interface whose IP address will be used as the source IP in the outer IP header of VXLAN encapsulated packets. This is essential for VTEP reachability and tunnel establishment.

Why this answer

The correct command to set the source interface for VXLAN tunnels on a Cisco Nexus 9000 NVE interface is 'source-interface loopback0'. This command ensures that the loopback0 IP address is used as the source IP for VXLAN encapsulated traffic, which is critical for VTEP reachability and proper tunnel establishment. Without it, the NVE interface cannot function correctly.

Exam trap

The trap here is confusing the NVE source interface command with similar commands used in other contexts, such as 'source-interface' under NTP or 'interface loopback0' to enter interface configuration.

54
Multi-Selectmedium

A network engineer is deploying a VXLAN EVPN fabric on Cisco Nexus 9000 switches. The engineer must configure the NVE interface and ensure proper VXLAN data plane operation. Which two statements about VXLAN EVPN configuration on Nexus 9000 are true? (Choose two.)

Select 2 answers
A.The EVPN control plane requires BGP to be configured with the EVPN address family on the spine and leaf switches.
B.VXLAN uses a 24-bit VNI field, allowing for up to 16 million unique VNIs.
C.The NVE interface must be configured with a source interface that is reachable via the underlay routing protocol.
D.Each VNI must be mapped to a unique VLAN on every leaf switch in the fabric.
E.The NVE interface must be configured with a multicast group for broadcast, unknown unicast, and multicast (BUM) traffic.
AnswersA, C

In a VXLAN EVPN fabric, BGP is used as the EVPN control plane. The spine and leaf switches must be configured with the EVPN address family (address-family l2vpn evpn) to exchange EVPN routes. This allows the fabric to learn MAC addresses and IP addresses dynamically, reducing the need for flooding. Without BGP EVPN, the fabric would rely on data plane learning, which is less efficient. Thus, this statement is true for Nexus 9000 VXLAN EVPN configuration.

Why this answer

The NVE interface requires a reachable source interface for VXLAN tunnels to form, and the EVPN control plane relies on BGP with the EVPN address family to exchange MAC and IP reachability information. These two statements are true for VXLAN EVPN configuration on Nexus 9000. The other options are either general VXLAN facts not specific to EVPN configuration, incorrect requirements, or applicable only to flood-and-learn VXLAN.

Exam trap

The trap here is assuming that multicast is always required for BUM traffic in VXLAN, when in EVPN deployments ingress replication can be used instead, making multicast optional.

55
MCQeasy

A network engineer is configuring a Cisco CSR 1000v router in a virtualized environment. The engineer needs to ensure that the router can forward traffic between multiple virtual routing and forwarding (VRF) instances while maintaining isolation. Which technology should the engineer use to allow communication between specific VRFs?

A.VRF leaking
B.Policy-based routing
C.VLAN trunking
D.GRE tunneling
AnswerA

VRF leaking allows routes to be selectively imported and exported between VRF instances, enabling controlled communication while maintaining isolation for other traffic. This is the standard method to allow specific inter-VRF communication on Cisco IOS-XE routers without merging the routing tables entirely.

Why this answer

VRF leaking is the correct technology because it allows specific routes to be imported from one VRF into another, enabling controlled communication while preserving isolation. This is typically done using route targets and route maps. Other options like GRE tunneling or policy-based routing can be used in specific cases but are not the standard method for inter-VRF communication on a single router.

Exam trap

The trap here is thinking that any tunneling or routing policy can enable inter-VRF communication, when VRF leaking is the specific and standard feature designed for this purpose.

56
Matchingmedium

Match each Cisco switch security feature to its function.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Limits MAC addresses on a port

Filters untrusted DHCP messages

Validates ARP packets

Prevents IP spoofing

Limits broadcast/multicast traffic

Why these pairings

Port Security limits MAC addresses per port to prevent MAC flooding. DHCP Snooping filters DHCP messages to block rogue servers. Dynamic ARP Inspection validates ARP packets using DHCP snooping entries to prevent spoofing.

IP Source Guard filters IP traffic based on the binding table to prevent IP spoofing. Common confusions include swapping these functions, e.g., assigning ARP spoofing prevention to Port Security or MAC flooding prevention to DHCP Snooping.

57
MCQmedium

A network engineer is deploying a VXLAN EVPN fabric on Cisco Nexus 9000 switches. The design requires that all VTEPs in the fabric learn the IP addresses of remote VTEPs so that BUM traffic can be replicated using ingress replication. Which control-plane component is responsible for distributing this VTEP IP address information across the fabric?

A.The EVPN Type-3 route carrying the VTEP loopback address and VNI membership
B.The PIM Anycast-RP configuration on the spine switches
C.The EVPN Type-5 route carrying IP prefix reachability for the tenant VRF
D.The EVPN Type-2 route carrying MAC and IP address bindings for host endpoints
AnswerA

EVPN Type-3 (Inclusive Multicast Ethernet Tag) routes advertise the originating VTEP's loopback IP address along with the VNI and Ethernet tag information. Receiving VTEPs build an ingress replication list from these advertisements, allowing them to replicate broadcast, unknown-unicast, and multicast traffic to every remote VTEP in the same VNI. This is exactly the control-plane mechanism the design requires.

Why this answer

Ingress replication requires each VTEP to know the loopback IP address of every other VTEP participating in the same VNI. EVPN Type-3 Inclusive Multicast Ethernet Tag routes serve precisely this purpose, advertising the originating VTEP IP, VNI, and Ethernet tag. Type-2 handles host MAC/IP bindings, Type-5 handles IP prefix advertisement, and PIM belongs to multicast replication designs.

Exam trap

The trap here is assuming that any EVPN route type distributing reachability information also distributes VTEP addresses for replication, when only the Inclusive Multicast Ethernet Tag route does that job.

58
MCQmedium

A network engineer at a university is deploying Cisco HyperFlex to replace a legacy SAN-backed vSphere cluster. The design calls for fabric interconnects to be managed in Cisco UCS Manager, and the engineer wants the HyperFlex installer to fully configure the fabric interconnects and the UCS servers automatically. Which HyperFlex deployment model should the engineer choose?

A.HyperFlex standard cluster with fabric interconnects in UCS Manager-managed mode
B.HyperFlex Edge with a two-node cluster managed by the HyperFlex Connect appliance
C.Cisco UCS Mini with HyperFlex software installed manually on each node
D.HyperFlex stretched cluster across two sites using Cisco Intersight-managed fabric interconnects
AnswerA

A standard HyperFlex cluster with UCS Manager-managed fabric interconnects lets the HyperFlex installer discover and configure the fabric interconnects, server policies, and VLANs automatically. This matches the requirement for automated configuration of both fabric interconnects and UCS servers in a data-center cluster, which is exactly what the standard deployment model delivers.

Why this answer

Deploying a standard HyperFlex cluster with UCS Manager-managed fabric interconnects is the model in which the HyperFlex installer discovers and configures the fabric interconnects, server profiles, and networking automatically. Because the university wants full automation of fabric interconnect and UCS server configuration in a data-center cluster, the standard model is the only listed option that satisfies every stated requirement.

Exam trap

The trap here is assuming any HyperFlex deployment automatically configures fabric interconnects, when Edge and Intersight-managed models use different management and validation workflows.

59
Multi-Selecthard

A network architect is evaluating VXLAN as the data plane encapsulation for a new data center fabric. Which two statements accurately describe how VXLAN operates? (Choose two.)

Select 2 answers
A.VXLAN replaces the original Ethernet header with a new one and discards the original source MAC.
B.VXLAN tunnel endpoints must use the same IP address to form a tunnel.
C.VXLAN encapsulates original Layer 2 frames inside UDP datagrams sent to destination port 4789.
D.VXLAN uses a 24-bit VXLAN Network Identifier, allowing over 16 million logical segments.
E.VXLAN requires the underlay to be a single Layer 2 domain with no routing between VTEPs.
AnswersC, D

VXLAN uses MAC-in-UDP encapsulation with the standard destination UDP port 4789. The original Ethernet frame is carried inside the UDP payload, allowing Layer 2 segments to be stretched across a Layer 3 underlay. This is a defining operational characteristic of VXLAN and is accurate for this fabric design.

Why this answer

VXLAN encapsulates original Layer 2 frames in UDP datagrams destined for port 4789 and identifies each logical segment with a 24-bit VNI supporting about 16 million segments. These two properties let the fabric scale far beyond VLAN limits while running over a routed Layer 3 underlay between distinct VTEP addresses.

Exam trap

The trap here is assuming VXLAN still depends on a flat Layer 2 underlay or a 12-bit segment identifier like traditional VLANs.

60
MCQmedium

A network engineer is deploying a new branch office that uses Cisco SD-WAN with a single transport underlay. The design requires that the branch router participate in the SD-WAN fabric and establish control connections to the controllers. Which component must the engineer configure on the branch device to allow it to register with the SD-WAN controllers and receive policy from vManage?

A.A unique system IP address and organization name configured on the device
B.An IPsec pre-shared key matching the vBond controller
C.A VRF named TRANSPORT with an OSPF process advertising the system IP
D.A BGP autonomous system number peering with the vSmart controller
AnswerA

The system IP and organization name are the two identifiers the SD-WAN controllers use to authenticate and track a device. Without a matching organization name and a unique system IP, the device cannot establish control connections to vBond, vSmart, and vManage, so it will not receive centralized policy or join the overlay.

Why this answer

For a Cisco SD-WAN device to join the overlay, it must be configured with a unique system IP address and the same organization name as the controllers. These values are used during the initial vBond handshake and subsequent control connections to vSmart and vManage. Without them, the device cannot authenticate, receive centralized policy, or participate in the fabric.

Exam trap

The trap here is assuming that an underlay routing protocol such as BGP or OSPF with the controllers is required for registration, when in fact the SD-WAN control plane uses TLS/DTLS tunnels authenticated by organization name and system IP.

61
MCQmedium

Refer to the exhibit. A network engineer has configured VRFs on a router. A packet arrives on Gi0/1/0 with destination IP 10.1.1.2. Which VRF is used for routing this packet?

A.Global routing table
B.Mgmt-intf
C.CUSTOMER-B
D.CUSTOMER-A
AnswerD

The packet enters via Gi0/1/0, and the exhibit shows this interface is configured in VRF CUSTOMER-A. When a packet arrives on an interface, the router immediately associates it with that interface's VRF and performs the destination IP lookup in the corresponding VRF-specific routing table. Because Gi0/1/0 belongs to CUSTOMER-A, the forwarding decision uses the routes, next hops, and constructs (e.g., VRF-specific ARP or CEF) belonging to CUSTOMER-A. This is why CUSTOMER-A is the correct answer.

Why this answer

The packet arrives on interface Gi0/1/0, which is configured under VRF CUSTOMER-A (as shown in the exhibit with 'ip vrf forwarding CUSTOMER-A'). When a VRF is applied to an ingress interface, the router uses that VRF's routing table (not the global table) to perform the destination IP lookup. Therefore, the packet with destination 10.1.1.2 is routed using the CUSTOMER-A VRF.

Exam trap

Cisco often tests the concept that the VRF used for routing is determined by the ingress interface's VRF assignment, not by the destination IP address or any other packet attribute, leading candidates to mistakenly assume the global table is used when no VRF is explicitly mentioned in the routing lookup.

How to eliminate wrong answers

Option A is wrong because the global routing table is used only when the ingress interface is not associated with any VRF, or when the VRF is explicitly bypassed (e.g., via 'ip route vrf' commands); here Gi0/1/0 is VRF-aware. Option B is wrong because 'Mgmt-intf' is a special VRF used exclusively for management traffic (e.g., SSH, SNMP) on the management interface, not for data-plane forwarding on Gi0/1/0. Option C is wrong because CUSTOMER-B is a different VRF; the interface Gi0/1/0 is bound to CUSTOMER-A, not CUSTOMER-B, so the router will not use CUSTOMER-B's routing table for this packet.

62
MCQmedium

A network engineer is troubleshooting a Cisco Nexus 9000 leaf switch in a VXLAN EVPN fabric. Hosts in VLAN 200 on one leaf cannot reach hosts in VLAN 200 on a remote leaf, although the Type 2 routes are present in the EVPN table. The engineer confirms that the local VTEP address is correct. Which action should the engineer take to verify that the VNI is properly mapped to the VLAN and that traffic is placed into the correct overlay?

A.Run show ip route vrf all to confirm that the tenant prefixes are installed in the routing table
B.Run show bgp l2vpn evpn to confirm that the Type 2 routes are received from the remote leaf
C.Run show interface nve1 to confirm that the NVE interface is administratively up and has the correct source address
D.Run show vxlan vni to confirm the VNI-to-VLAN mapping and check the VXLAN interface state
AnswerD

The show vxlan vni command displays the mapping between VLANs and VNIs and indicates whether the VXLAN interface is up. If the VLAN-to-VNI mapping is missing or the VXLAN interface is down, hosts cannot be placed into the correct overlay, which matches the symptom of remote reachability failing despite EVPN routes being present.

Why this answer

The show vxlan vni command reveals the VLAN-to-VNI bindings and the state of the VXLAN interface, which is exactly what must be validated when hosts in the same VLAN cannot communicate across leaves despite EVPN routes being present. Routing table, EVPN table, and NVE interface checks address different layers and do not confirm the overlay mapping for VLAN 200.

Exam trap

The trap here is assuming that receiving EVPN routes proves the local overlay mapping is correct, when a missing VLAN-to-VNI binding still breaks forwarding.

63
MCQhard

A network engineer configured a Cisco IOS-XE router with VRF CUSTOMER_A and assigned Gi0/0/1 to it. The interface is up and has an IP address, but traffic sourced from the VRF cannot reach a remote prefix that is present in the global routing table. The engineer confirms the global route exists and the next hop is reachable. What is the most likely cause?

A.The interface must be configured with the ip vrf forwarding command a second time
B.The global routing table entry is a recursive route that cannot be resolved
C.CEF is disabled on the router, forcing all traffic to be process-switched
D.The VRF has no route to the destination and requires route leaking or a default route
AnswerD

A VRF maintains its own separate routing and forwarding table, so prefixes in the global table are not automatically visible inside CUSTOMER_A. Because the destination prefix exists only in the global table, the VRF has no matching route and drops the traffic. The engineer must either leak the global prefix into the VRF or provide a default route within the VRF.

Why this answer

VRFs create fully isolated routing and forwarding tables on the same physical router. A prefix installed in the global table is not automatically available inside a VRF, and vice versa. To allow the VRF to reach that destination, the engineer must either redistribute or leak the route between the global table and the VRF, or install a default route inside the VRF.

Exam trap

The trap here is assuming that a route visible in the global routing table is automatically usable by traffic sourced inside a VRF.

64
MCQeasy

A network engineer is configuring a Cisco IOS-XE router to support virtual routing and forwarding (VRF). The engineer wants to ensure that the VRF can be used for MPLS VPN and that the router can maintain separate routing tables. Which command is used to create a VRF named CUSTOMER?

A.vrf definition CUSTOMER
B.ip vrf CUSTOMER
C.interface vrf CUSTOMER
D.vrf CUSTOMER
AnswerA

The 'vrf definition CUSTOMER' command in global configuration mode creates a VRF instance named CUSTOMER. This command is used in Cisco IOS-XE to define a VRF and enter VRF configuration mode, where you can specify address families, route targets, and other parameters. It is the correct way to create a VRF for MPLS VPN or other segmentation purposes.

Why this answer

The correct command to create a VRF named CUSTOMER on a Cisco IOS-XE router is 'vrf definition CUSTOMER'. This command creates the VRF and enters VRF configuration mode, allowing the engineer to configure address families and other parameters. The 'ip vrf' command is an older alternative but lacks support for IPv6 and is not recommended for new deployments.

Exam trap

The trap here is assuming that 'ip vrf' is still the preferred command for creating VRFs on modern IOS-XE routers, when in fact 'vrf definition' is the current standard that supports both IPv4 and IPv6 address families.

65
MCQmedium

A network engineer is deploying a Cisco SD-Access fabric using Cisco DNA Center. The design requires that endpoints in the same virtual network (VN) be able to communicate even when they are attached to different fabric edge nodes. Which data plane technology does SD-Access use to carry the endpoint traffic across the fabric underlay?

A.MPLS L3VPN with a route target per virtual network
B.GRE with a tunnel key per virtual network
C.OTV with an overlay VLAN per virtual network
D.VXLAN with a fabric VNI mapped to each virtual network
AnswerD

SD-Access uses VXLAN encapsulation in the fabric data plane. Each virtual network is mapped to a unique VNI, and the fabric edge nodes and border nodes act as VTEPs. The endpoint traffic is carried inside VXLAN tunnels across the underlay, which allows Layer 2 and Layer 3 communication between endpoints attached to different edge nodes while maintaining segmentation.

Why this answer

Cisco SD-Access uses VXLAN as the data plane encapsulation. Each virtual network is mapped to a unique VNI, and the fabric edge and border nodes encapsulate endpoint traffic in VXLAN. This allows endpoints in the same VN to communicate across different edge nodes while preserving segmentation.

The control plane uses LISP to map endpoint identities to fabric locations.

Exam trap

The trap here is confusing the SD-Access data plane with other tunneling technologies like GRE or MPLS, which are not used inside the SD-Access fabric.

66
MCQhard

A financial services company has deployed Cisco UCS servers with VMware vSphere 7.0 to host critical trading applications. The network uses Cisco Nexus 9000 switches in a VXLAN EVPN fabric with BGP as the underlay. The environment includes 50 ESXi hosts, each connected via two 40G interfaces to two different leaf switches in a VPC. The VMs are spread across multiple hosts and communicate over VXLAN. Recently, the operations team migrated a set of VMs from an old VLAN-based network to a new VXLAN segment (VNI 50000). After the migration, users report intermittent connectivity issues and packet loss. The engineering team captures traffic and notices that some VMs send ARP requests that are not being replied to, even though the target VM is active. Further analysis shows that the ARP requests are being flooded to all VTEPs, but the replies are not reaching the source. The team checks the underlay and finds no issues with BGP or routing. The NVE interfaces are up, and the VNI is configured. Which of the following is the most likely cause of the issue?

A.The ingress replication list is missing some VTEPs.
B.The symmetric routing configuration is missing on the leaf switches.
C.The VPC configuration between the leaf switches and ESXi hosts is incorrect.
D.The MAC address of the target VM is not being advertised in EVPN type-2 routes because the VM's MAC is learned on a different leaf switch than expected.
AnswerD

In EVPN, each leaf switch advertises locally learned MAC addresses via MP-BGP Type-2 routes. If the target VM's MAC is learned on a leaf different from the one the source leaf expects, or if that leaf has not advertised the route, the source leaf has no EVPN entry for that MAC. It floods the ARP request as BUM, but the reply is sent as unicast, and without a Type-2 route the source cannot properly deliver or cache the reply, leading to unidirectional communication failure.

Why this answer

The issue is that the target VM's MAC address is not being advertised via EVPN Type-2 routes from the leaf switch where it resides. When the source VM sends an ARP request, the ingress VTEP floods it to all VTEPs in the VNI's ingress replication list, but the reply from the target VM must be unicast back. If the target's MAC is not in the EVPN control plane (e.g., because it was learned on a different leaf than expected due to asymmetric MAC learning or stale entries), the reply cannot be forwarded correctly, causing intermittent connectivity.

Exam trap

Cisco often tests the distinction between data-plane flooding (which works) and control-plane advertisement (which fails), leading candidates to incorrectly blame replication lists or VPC issues instead of identifying the missing EVPN Type-2 route.

How to eliminate wrong answers

Option A is wrong because if the ingress replication list were missing some VTEPs, the ARP requests would not reach those VTEPs at all, but the problem states the ARP requests are flooded to all VTEPs, so the list is complete. Option B is wrong because symmetric routing is a design choice for inter-VNI routing (e.g., between different VNIs), not for intra-VNI ARP handling within the same VNI; the issue is about MAC/IP advertisement, not routing asymmetry. Option C is wrong because the VPC configuration between leaf switches and ESXi hosts affects link-level redundancy and loop prevention, but the underlay is healthy and NVE interfaces are up, so VPC misconfiguration would cause connectivity issues unrelated to ARP reply forwarding.

67
MCQhard

A network engineer is configuring a Cisco Nexus 9000 switch in a VXLAN EVPN fabric. The engineer wants to ensure that the switch can advertise MAC addresses learned from local hosts to other VTEPs. Which EVPN route type is used to advertise MAC address reachability information?

A.Type 2 - MAC/IP Advertisement route
B.Type 3 - Inclusive Multicast Ethernet Tag route
C.Type 1 - Ethernet Auto-Discovery route
D.Type 5 - IP Prefix route
AnswerA

Type 2 EVPN routes are used to advertise MAC addresses and optionally IP addresses. When a VTEP learns a MAC address from a local host, it generates a Type 2 route and advertises it to other VTEPs via BGP EVPN. This allows remote VTEPs to learn the MAC-to-VTEP mapping and forward traffic correctly. Type 2 routes are essential for Layer 2 and Layer 3 VXLAN EVPN operation.

Why this answer

In EVPN, MAC address reachability is advertised using Type 2 routes, also known as MAC/IP Advertisement routes. When a VTEP learns a local MAC address, it creates a Type 2 route containing the MAC address, the VNI, and the next-hop VTEP IP. This route is distributed via BGP EVPN to other VTEPs, enabling them to build the MAC-to-VTEP mapping for forwarding.

Exam trap

The trap here is mixing up EVPN route types; Type 2 is for MAC/IP advertisement, while Type 3 is for multicast and Type 5 is for IP prefixes.

68
Multi-Selectmedium

A network architect is designing a data center fabric that uses VXLAN with an EVPN control plane on Cisco Nexus 9000 switches. The architect must justify why EVPN is preferred over a flood-and-learn VXLAN data plane. Which two statements correctly describe advantages of using an EVPN control plane in this design? (Choose two.)

Select 2 answers
A.It distributes MAC address reachability through BGP so VTEPs do not need to flood frames to learn remote host locations
B.It converts VXLAN tunnels into MPLS LSPs to improve forwarding performance between leaf switches
C.It eliminates the need for any underlay routing protocol because BGP carries all traffic between leaf switches
D.It removes the requirement for a loopback interface on each VTEP by using physical interface addresses
E.It supports multihoming of servers to two leaf switches with all-active forwarding using Ethernet Segment identifiers
AnswersA, E

With EVPN, MAC and IP bindings are advertised as BGP route types, so each VTEP learns remote host locations from the control plane rather than from data-plane flooding. This reduces unknown-unicast flooding and speeds convergence. In a flood-and-learn design, every VTEP must flood to discover remote MACs, which wastes bandwidth and creates scaling problems in large fabrics.

Why this answer

An EVPN control plane advertises MAC and IP reachability via BGP, avoiding data-plane flooding for host learning, and it supports standards-based all-active multihoming through Ethernet Segment identifiers and DF election. It does not remove the underlay routing requirement, convert VXLAN to MPLS, or eliminate the VTEP loopback, so those statements are incorrect for this design.

Exam trap

The trap here is conflating the overlay control plane with the underlay transport, leading to the false belief that EVPN removes the need for underlay routing or VTEP loopbacks.

69
MCQmedium

A network engineer is deploying Cisco ACI in a data center. The requirement is to allow an external Layer 3 router to dynamically learn the endpoints that reside in a specific bridge domain (BD) and to advertise the BD's subnet to the external network. The external router is connected to a border leaf switch. Which Cisco ACI construct must be configured to meet this requirement?

A.A VRF with a contract that permits all traffic between the external router and the BD.
B.A bridge domain with unicast routing enabled and a contract to the external EPG.
C.An L3Out with an external EPG and OSPF or BGP peering to the external router.
D.An EPG with a static path binding to the external router's interface.
AnswerC

An L3Out defines the Layer 3 connection to an external router. It includes an external EPG that represents the external network, and routing protocols like OSPF or BGP can be configured to exchange routes. The border leaf advertises the BD subnet and learns external routes, enabling dynamic endpoint reachability. This is the correct construct for external Layer 3 connectivity.

Why this answer

The L3Out construct in Cisco ACI is designed for external Layer 3 connectivity. It includes an external EPG and supports routing protocols such as OSPF, BGP, or EIGRP. By configuring an L3Out on the border leaf, the fabric can peer with the external router, advertise the bridge domain subnet, and learn external routes.

Contracts are for policy, not route exchange, and static path bindings are for Layer 2 connectivity.

Exam trap

The trap here is confusing contracts or static path bindings with the routing protocol peering that only an L3Out provides for external Layer 3 connectivity.

70
MCQmedium

A network engineer is designing a new data center leaf-spine fabric using Cisco Nexus 9000 switches. The design requires that the fabric automatically discover the IP addresses of remote VTEPs participating in a VXLAN EVPN deployment. Which control-plane protocol should be enabled on the leaf switches to provide this dynamic VTEP discovery?

A.OSPFv3 in the underlay network
B.Protocol Independent Multicast (PIM) sparse mode
C.Cisco Fabric Services (CFS) over the management network
D.Multiprotocol BGP with EVPN address family
AnswerD

MP-BGP with the EVPN address family is the control plane for VXLAN EVPN. It advertises Type-2 and Type-3 routes that carry VTEP IP addresses, enabling automatic discovery of remote VTEPs. Without it, VTEPs must be statically configured, losing the dynamic fabric benefits of EVPN.

Why this answer

VXLAN EVPN uses MP-BGP with the EVPN address family as the overlay control plane. It advertises Type-2 (MAC/IP) and Type-3 (IMET) routes, allowing leaf switches to learn remote VTEP IP addresses automatically. This eliminates the need for static VTEP configuration and supports efficient multi-tenancy and mobility.

Exam trap

The trap here is confusing the underlay routing protocol (such as OSPF or IS-IS) with the overlay control plane that actually carries VTEP reachability and MAC/IP bindings.

71
MCQhard

A network engineer is deploying Cisco ACI in a data center. The engineer needs to configure a bridge domain that allows traffic to be routed between two EPGs that are in different subnets. Which ACI object must be configured to enable inter-subnet routing within the bridge domain?

A.Bridge domain with unicast routing enabled and subnets configured
B.Subnet under the bridge domain with a scope of 'Advertised Externally'
C.VRF
D.Contract
AnswerA

To enable inter-subnet routing within a bridge domain, you must configure the bridge domain with unicast routing enabled and define the subnets on the bridge domain. This allows the ACI fabric to route between EPGs in different subnets that are part of the same bridge domain.

Why this answer

Inter-subnet routing in Cisco ACI is enabled by configuring a bridge domain with unicast routing turned on and defining the necessary subnets. This allows the fabric to act as the default gateway for endpoints in those subnets and route traffic between them, even if they are in different EPGs.

Exam trap

The trap here is assuming that a contract or VRF alone enables inter-subnet routing, when the bridge domain must have unicast routing enabled and subnets defined.

72
Multi-Selecthard

A network engineer is troubleshooting a Cisco Nexus 9000 VXLAN EVPN fabric in which a host attached to leaf-1 cannot communicate with a host in the same subnet attached to leaf-2, even though both leaf switches show the VNI as up. The engineer suspects the EVPN control plane. Which two conditions must be met for the two hosts to communicate over the VXLAN overlay? (Choose two.)

Select 2 answers
A.The two leaf switches must establish a BGP EVPN session, either directly or through a route reflector, and exchange MAC or MAC-IP routes for the VNI.
B.The spines must terminate the VXLAN tunnels and perform the inter-VTEP forwarding between the two leaf switches.
C.Each leaf's NVE source interface must be reachable in the underlay, and the remote VTEP IP must be present in the local VRF or global table.
D.The two leaf switches must use the same VLAN ID locally for the segment, because the VLAN ID is carried inside the VXLAN header.
E.The two leaf switches must have identical bridge domain configurations, including the same anycast gateway MAC address on every leaf.
AnswersA, C

VXLAN EVPN relies on MP-BGP EVPN to advertise MAC and MAC-IP reachability between VTEPs. Without an established EVPN session and the corresponding type-2 routes for the VNI, leaf-1 does not know which remote VTEP owns the destination MAC, so it cannot encapsulate the frame toward leaf-2 and traffic is dropped even though the VNI is up.

Why this answer

For hosts in the same subnet on different leaves to communicate, the fabric needs both control-plane and data-plane reachability. The EVPN session must advertise the type-2 MAC or MAC-IP routes for the VNI so each leaf learns the remote VTEP for the destination, and the underlay must be able to deliver encapsulated packets to that remote VTEP IP. Missing either element leaves the VNI up but the hosts unable to reach each other.

Exam trap

The trap here is thinking the VNI being up means the overlay is working, when EVPN route exchange and VTEP IP reachability are the actual requirements.

73
MCQmedium

A network engineer is deploying a VXLAN EVPN fabric with Cisco Nexus 9000 switches. The design requires that when a leaf switch learns a MAC address from a local host, remote leaf switches should be able to install that MAC into their forwarding tables without flooding. Which EVPN route type is used to advertise MAC address reachability?

A.Type 5 IP Prefix route
B.Type 3 Inclusive Multicast Ethernet Tag route
C.Type 2 MAC/IP Advertisement route
D.Type 1 Ethernet Auto-Discovery route
AnswerC

Type 2 MAC/IP Advertisement routes carry the MAC address, IP address, and VTEP information for a host, allowing remote leaf switches to install the MAC into their forwarding tables without flooding. This route type is the core of EVPN MAC learning and enables efficient unicast forwarding across the VXLAN fabric. It directly satisfies the requirement for MAC reachability advertisement.

Why this answer

EVPN Type 2 MAC/IP Advertisement routes are specifically designed to advertise host MAC and IP addresses along with the originating VTEP. Remote leaf switches receive these routes and program the MAC into their forwarding tables, enabling known unicast traffic to be sent directly without flooding. Other EVPN route types serve different purposes such as multihoming, BUM replication, or Layer 3 prefix advertisement.

Exam trap

The trap here is confusing the EVPN route types, especially mixing up Type 2 MAC advertisement with Type 3 BUM replication.

74
MCQhard

An engineer is configuring a Cisco Nexus 9000 switch as a VXLAN Tunnel Endpoint in a spine-leaf fabric. The requirement is that the switch must perform VXLAN encapsulation and decapsulation in hardware without relying on the supervisor CPU, and it must support distributed anycast gateway for the tenant subnets. Which feature set must be enabled to meet these requirements?

A.Traditional Layer 2 switching with STP
B.Cisco NX-OS with the VXLAN feature and distributed anycast gateway enabled
C.Cisco ACI with a fabric-wide VXLAN pool
D.Cisco Nexus Dashboard with fabric controller mode
AnswerB

On Nexus 9000 switches, enabling the VXLAN feature allows the hardware ASIC to perform VXLAN encapsulation and decapsulation at line rate, avoiding supervisor CPU involvement. Configuring a distributed anycast gateway with the same virtual IP and MAC on every leaf provides optimal first-hop routing for tenant subnets. Together these features satisfy both the hardware-based VXLAN data plane and the anycast gateway design requirement.

Why this answer

Nexus 9000 switches support VXLAN encapsulation and decapsulation in hardware once the VXLAN feature is enabled, keeping forwarding off the supervisor CPU. A distributed anycast gateway configured with a shared virtual IP and MAC across leaf switches provides efficient first-hop routing for tenant subnets, meeting both requirements for this VXLAN Tunnel Endpoint design.

Exam trap

The trap here is confusing a centralized management or SDN platform with the on-switch feature set that actually delivers hardware VXLAN forwarding and distributed anycast gateway.

75
MCQhard

A network engineer is troubleshooting a VXLAN EVPN fabric on Cisco Nexus 9000 switches. Hosts in VLAN 100 on different leaf switches cannot communicate, even though the EVPN control plane shows the MAC addresses. The engineer suspects a problem with the VXLAN data plane. Which command should be used to verify the VXLAN tunnel endpoints (VTEPs) and their status?

A.show vxlan interface
B.show bgp l2vpn evpn
C.show nve peers
D.show ip arp vrf all
AnswerC

This command displays the status of VXLAN tunnel endpoints (VTEPs) and their peering relationships. It shows the IP addresses of remote VTEPs, the VNI, and the state of the tunnel. If the tunnel is down, this command will indicate that, helping the engineer identify why hosts cannot communicate despite EVPN MAC entries.

Why this answer

The 'show nve peers' command is used to verify the status of VXLAN tunnel endpoints and their peering relationships. It provides details such as the remote VTEP IP, VNI, and tunnel state. If the tunnel is down, this command helps identify the issue, which is critical when EVPN control plane information is present but data plane connectivity is failing.

Exam trap

The trap here is assuming that control plane verification (such as BGP EVPN routes) is sufficient to confirm data plane connectivity, when in fact VXLAN tunnel status must be checked separately.

Page 1 of 2 · 93 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Virtualization questions.