Courseiva

CCNA Virtualization Questions

18 of 93 questions · Page 2/2 · Virtualization · Answers revealed

76
MCQmedium

A network engineer is configuring a Cisco Nexus 9000 switch as a VXLAN Tunnel Endpoint (VTEP) in a spine-leaf fabric. The engineer needs to verify that the NVE interface is operational and that the VNI-to-VLAN mapping is correct. Which command should the engineer use to display the VXLAN tunnel endpoints and their associated VNIs?

A.show nve vni
B.show nve interface nve1
C.show nve peers
D.show vxlan vni
AnswerA

The 'show nve vni' command displays the VNIs configured on the NVE interface along with their associated VLANs, the VNI state, and the multicast group or peer information. This directly verifies the VNI-to-VLAN mapping and confirms that the NVE interface is operational. It is the most comprehensive command for checking both the VTEP status and the VNI mapping, making it the correct choice for this scenario.

Why this answer

The engineer needs to verify both the NVE interface operational status and the VNI-to-VLAN mapping. The 'show nve vni' command provides a comprehensive view of the VNIs, their associated VLANs, and the state of each VNI, which directly addresses the requirement. Other commands show partial information, such as peers or interface details, but do not combine the mapping and operational status in one output.

Exam trap

The trap here is assuming that 'show nve peers' or 'show nve interface' alone can verify the VNI-to-VLAN mapping, when in fact only 'show nve vni' displays that mapping along with VNI state.

77
MCQeasy

Which component of Cisco ACI is responsible for policy enforcement and forwarding decisions?

A.Cisco Nexus Dashboard
B.Leaf switch
C.Spine switch
D.APIC
AnswerB

Leaf switches in Cisco ACI are responsible for policy enforcement and forwarding decisions. They connect to endpoints (servers, storage, etc.) and apply the policies defined by the APIC. The leaf switches maintain the forwarding tables and enforce contracts between endpoint groups.

Why this answer

Leaf switches in Cisco ACI are responsible for policy enforcement and forwarding decisions. They connect to endpoints and apply the policies programmed by the APIC. The APIC manages the policies, but the leaf switches enforce them and forward traffic based on those policies.

Exam trap

The trap here is assuming that the APIC, as the controller, also enforces policies, but in ACI, the data plane enforcement is done by the leaf switches.

78
MCQmedium

A network engineer is configuring a Cisco Nexus 9000 switch with VXLAN EVPN. The engineer wants to ensure that the switch can forward traffic between VLANs that are mapped to the same VXLAN Network Identifier (VNI) but are on different leaf switches. Which component is responsible for mapping the VLAN to the VNI on the ingress leaf switch?

A.Ingress replication
B.VLAN-to-VNI mapping
C.VXLAN Tunnel Endpoint (VTEP)
D.EVPN route type 2
AnswerB

The VLAN-to-VNI mapping is configured on the ingress leaf switch to associate a VLAN with a VNI. When a frame arrives on an access port in a VLAN, the switch uses this mapping to encapsulate the frame in VXLAN with the corresponding VNI. This allows Layer 2 connectivity to be extended across the VXLAN fabric. The mapping is typically configured under the VLAN configuration or via a VLAN-VNI mapping command. Without this mapping, the switch would not know which VNI to use for encapsulation.

Why this answer

The VLAN-to-VNI mapping is the component that associates a VLAN with a VNI on the ingress leaf switch. When a frame enters the access port, the switch uses this mapping to encapsulate it in VXLAN with the correct VNI. EVPN route type 2 is for MAC/IP advertisement, the VTEP encapsulates and decapsulates VXLAN traffic, and ingress replication is used for BUM traffic handling.

Only the VLAN-to-VNI mapping directly performs the required function.

Exam trap

The trap here is confusing the VTEP with the VLAN-to-VNI mapping, as the VTEP uses the mapping but is not the mapping itself.

79
MCQmedium

A network engineer is configuring a Cisco CSR 1000v router to run multiple virtual routing and forwarding (VRF) instances. The engineer wants to ensure that traffic from VRF RED can reach the internet while traffic from VRF BLUE remains isolated. Which feature should be configured to allow VRF RED to access the global routing table?

A.MPLS L3VPN with route targets
B.GRE tunnel between VRF RED and the global table
C.VRF-lite with OSPF process per VRF
D.Route leaking using static routes with next-hop in the global table
AnswerD

Route leaking allows selective import of routes between VRFs or between a VRF and the global table. By configuring a static route in VRF RED pointing to a global next-hop, or by using BGP import/export, you can allow VRF RED to reach the internet while keeping VRF BLUE isolated.

Why this answer

Route leaking is the correct feature to allow traffic from a specific VRF to access the global routing table or another VRF. By configuring static routes or BGP import/export, the engineer can selectively leak routes for VRF RED to the global table, enabling internet access while maintaining isolation for VRF BLUE.

Exam trap

The trap here is thinking that simply configuring a routing protocol within each VRF will allow internet access, when in fact inter-VRF or VRF-to-global communication requires route leaking.

80
MCQmedium

A data center team is deploying a VXLAN EVPN fabric on Cisco Nexus 9000 switches and wants to eliminate the need for multicast underlay replication for broadcast, unknown unicast, and multicast traffic. Which mechanism should the team implement to achieve ingress replication of BUM traffic?

A.Configure PIM sparse mode on all underlay interfaces
B.Enable IGMP snooping on all leaf access ports
C.Enable head-end replication using EVPN Type 3 routes
D.Configure MSDP peering between all leaf switches
AnswerC

EVPN Type 3 Inclusive Multicast Ethernet Tag routes advertise VTEP and VNI membership, letting each ingress VTEP build a replication list of remote VTEPs. The ingress leaf then replicates BUM frames individually to every remote VTEP, which is head-end or ingress replication. This removes the requirement for multicast in the underlay entirely.

Why this answer

With EVPN, Type 3 Inclusive Multicast Ethernet Tag routes advertise each VTEP's interest in a VNI, allowing ingress leaf switches to construct a list of remote VTEPs per VNI. BUM frames are then replicated by the ingress VTEP directly to each remote VTEP, which is head-end replication and removes the need for a multicast-capable underlay.

Exam trap

The trap here is confusing multicast replication in the underlay with EVPN-based ingress replication, which is signaled by Type 3 routes.

81
Multi-Selectmedium

A data center team is designing a VXLAN EVPN fabric on Cisco Nexus 9000 switches to replace an aging three-tier topology. They want to understand which functions are performed by the VXLAN tunnel endpoints and the EVPN control plane. Which two statements accurately describe VXLAN EVPN behavior? (Choose two.)

Select 2 answers
A.The VXLAN Network Identifier is a 12-bit field, limiting each fabric to 4094 segments.
B.VXLAN requires that the underlay fabric run only Layer 2 trunks between every leaf and spine.
C.VTEPs must be configured with the same IP address on every leaf switch to form a single tunnel endpoint.
D.VTEPs encapsulate original Layer 2 frames inside UDP packets destined to the remote VTEP IP address.
E.EVPN uses MP-BGP to distribute MAC and IP reachability information among VTEPs.
AnswersD, E

VXLAN data plane encapsulation wraps the original Ethernet frame in a VXLAN header, then UDP, IP and a new outer Ethernet header. The outer destination IP is the remote VTEP's loopback address, which is reachable over the routed underlay. This is precisely how frames cross the Layer 3 fabric between leaf switches in the scenario.

Why this answer

VXLAN encapsulates original frames in UDP and delivers them to a remote VTEP's IP address, while EVPN supplies a BGP-based control plane that distributes MAC and IP reachability so flooding is minimized. The underlay is routed, the VNI field is 24 bits wide, and each VTEP requires its own unique address, so the other statements misstate fundamental VXLAN EVPN design facts.

Exam trap

The trap here is mixing up the 12-bit VLAN ID with the 24-bit VXLAN Network Identifier when reasoning about segment scale.

82
Multi-Selectmedium

A network engineer is deploying Cisco ACI in a data center. The engineer needs to configure a bridge domain that provides Layer 2 connectivity between endpoints in the same tenant. Which two statements about Cisco ACI bridge domains are true? (Choose two.)

Select 2 answers
A.A bridge domain requires a VLAN pool to be defined in the fabric access policies.
B.A bridge domain can contain multiple subnets.
C.A bridge domain can only contain a single subnet.
D.A bridge domain provides Layer 3 routing between subnets by default.
E.A bridge domain must be associated with a VRF to provide Layer 3 routing.
AnswersB, E

A Cisco ACI bridge domain can have multiple subnets configured under it. Each subnet is associated with a gateway IP address on the ACI fabric. This allows a single bridge domain to support multiple IP subnets, providing flexibility in addressing and segmentation within the same Layer 2 domain.

Why this answer

In Cisco ACI, a bridge domain is a Layer 2 construct that can contain multiple subnets and must be associated with a VRF to enable Layer 3 routing. The VRF provides the routing context, and multiple subnets allow flexible IP addressing within the same bridge domain. VLAN pools are used for VLAN allocation but are not a direct requirement for the bridge domain itself.

Exam trap

The trap here is assuming that a bridge domain inherently provides Layer 3 routing or is limited to a single subnet, when in fact it requires VRF association for routing and supports multiple subnets.

83
MCQeasy

A network administrator is enabling a virtual routing and forwarding instance on a Cisco IOS-XE router to separate customer traffic. The administrator issues the ip vrf forwarding CUSTOMER_A command on Gi0/0/1, and the interface immediately loses its IP address. What is the reason for this behavior?

A.The router reloaded and lost the running configuration
B.The interface entered a shutdown state due to the VRF assignment
C.Assigning an interface to a VRF removes any previously configured IP address
D.The VRF was not yet created in global configuration mode
AnswerC

When an interface is moved into a VRF, Cisco IOS-XE removes its existing IP address because the address belonged to the global routing table. The administrator must re-enter the IP address after the VRF assignment so the interface has an address within the VRF's own address space. This is expected behavior, not a fault.

Why this answer

On Cisco IOS-XE, entering the ip vrf forwarding command on an interface moves that interface into the named VRF and removes any IP address previously configured in the global table. The address must be reapplied afterward so the interface participates in the VRF's routing and forwarding tables. This is normal, expected behavior.

Exam trap

The trap here is treating the disappearance of the IP address as a fault or a sign of a missing VRF, rather than as expected behavior when moving an interface between routing tables.

84
MCQmedium

A network engineer is troubleshooting a Cisco Nexus 9000 leaf switch that is part of a VXLAN EVPN fabric. The engineer notices that the leaf is not learning remote MAC addresses, although the underlay is operational and BGP EVPN sessions are established. Which action should the engineer take to verify that the leaf is receiving EVPN Type 2 routes?

A.Check the output of 'show vxlan interface' on the leaf.
B.Check the output of 'show ip route' on the leaf.
C.Check the output of 'show nve peers' on the leaf.
D.Check the output of 'show bgp l2vpn evpn' on the leaf.
AnswerD

The command 'show bgp l2vpn evpn' displays the EVPN routes received from BGP peers, including Type 2 (MAC/IP advertisement) routes. If the leaf is not learning remote MACs, this command will show whether Type 2 routes are present. If they are missing, the issue may be with the BGP EVPN configuration or route reflectors. This is the correct verification step.

Why this answer

To verify that the leaf is receiving EVPN Type 2 routes, you must examine the BGP EVPN table. The command 'show bgp l2vpn evpn' displays all EVPN routes, including Type 2 MAC/IP advertisement routes. If these routes are missing, the leaf will not learn remote MAC addresses.

Other commands like 'show nve peers' show VTEP peers but not MAC routes, and 'show vxlan interface' shows tunnel configuration, not routes.

Exam trap

The trap here is assuming that seeing NVE peers or underlay routes is sufficient to confirm MAC learning, when actually you need to inspect the BGP EVPN table for Type 2 routes.

85
MCQeasy

A company is consolidating branch servers onto a single physical host running a hypervisor. The administrator needs each virtual machine to have its own virtual NIC with an independent MAC address and to be isolated at Layer 2 from other virtual machines unless explicitly connected to the same virtual switch. Which component provides this function?

A.The hypervisor's virtual machine monitor alone
B.The physical top-of-rack switch
C.The virtual switch inside the hypervisor
D.A VLAN trunk configured on the physical NIC
AnswerC

A virtual switch connects virtual NICs within the hypervisor and forwards frames between them based on MAC addresses, giving each virtual machine its own vNIC and MAC. Virtual machines placed on different virtual switches or port groups remain isolated unless an uplink or explicit connection joins them, matching the requirement.

Why this answer

The virtual switch is the hypervisor component that gives each virtual machine a virtual NIC and forwards frames between them, enforcing isolation between port groups unless they are connected. The physical switch and trunk only carry traffic once it leaves the host, and the virtual machine monitor handles resource scheduling rather than Layer 2 forwarding.

Exam trap

The trap here is assuming the physical switch enforces isolation between virtual machines that live on the same hypervisor host.

86
MCQmedium

A network engineer is deploying a Cisco Nexus 9000 leaf switch in a VXLAN EVPN fabric. The underlay uses OSPF for loopback reachability, and the engineer must now enable the control plane that carries MAC and IP address reachability information for the overlay. Which technology must be enabled on the leaf switch to distribute this overlay reachability information?

A.LISP with a Map-Server and Map-Resolver
B.OSPFv3 with the IPv6 unicast address family
C.MP-BGP with the Layer 2 EVPN address family
D.PIM sparse mode with an Anycast-RP
AnswerC

EVPN uses MP-BGP with the L2VPN EVPN address family to advertise MAC addresses, IP-to-MAC bindings, and VTEP reachability in a VXLAN fabric. Enabling this address family in the leaf's BGP configuration lets the switch exchange Type 2 and Type 3 routes with the spine route reflectors, which is exactly the overlay control plane required here.

Why this answer

In a VXLAN EVPN fabric, the underlay (here OSPF) provides loopback-to-loopback reachability between VTEPs, while the overlay control plane is MP-BGP with the L2VPN EVPN address family. Enabling that address family allows the leaf to advertise MAC and IP address routes and VTEP membership through the spine route reflectors, replacing flood-and-learn with a scalable, standards-based control plane.

Exam trap

The trap here is assuming the routing protocol that provides underlay loopback reachability also carries overlay MAC and IP reachability information.

87
MCQmedium

A network administrator is configuring a Cisco IOS-XE router to support virtual routing and forwarding (VRF) for a customer. The administrator wants to ensure that traffic from the customer's VRF can reach the internet through a global routing table. Which feature should be configured to allow communication between the VRF and the global routing table?

A.VXLAN EVPN
B.VRF-aware NAT
C.MPLS Layer 3 VPN
D.Route leaking
AnswerD

Route leaking is the process of importing routes from one VRF into another, including the global routing table. By configuring route targets or using static routes with the global keyword, you can leak routes between a VRF and the global table. This allows traffic from the VRF to be routed to the internet via the global table, provided that the global table has a route to the destination.

Why this answer

Route leaking allows routes to be exchanged between VRFs, including the global routing table. By configuring route leaking, you can import routes from the global table into the VRF and export routes from the VRF to the global table. This enables communication between the VRF and the global table, allowing traffic to reach the internet.

Other features like NAT or MPLS L3VPN do not provide this local routing capability.

Exam trap

The trap here is thinking that NAT alone can connect a VRF to the global table; NAT translates addresses but does not provide the necessary routing information.

88
Multi-Selecteasy

Which TWO statements about virtual switching in a hypervisor environment are correct?

Select 2 answers
A.A virtual switch can be connected to a physical network through uplink ports.
B.A virtual switch does not support VLAN tagging.
C.A virtual switch performs routing between different subnets.
D.A virtual switch forwards frames between virtual machines based on MAC addresses.
E.A virtual switch is a physical device installed in the hypervisor host.
AnswersA, D

Uplink ports bind a virtual switch to physical NICs, bridging guest VM traffic onto the wired network. This satisfies the stem's requirement for correct virtual switching statements, since without uplinks, VMs on the vSwitch could only communicate internally, isolated from the physical infrastructure.

Why this answer

Option A is correct because a virtual switch (vSwitch) uses uplink ports, also called physical NICs or pNICs, to bridge virtual machine traffic onto the physical network, allowing VMs to communicate beyond the host. Option D is correct because a virtual switch operates at Layer 2, learning MAC addresses and forwarding Ethernet frames between virtual machines (and to uplinks) based on destination MAC addresses, just like a physical switch. Option B is wrong because virtual switches do support VLAN tagging, typically via VLAN IDs on port groups or virtual switch ports (e.g., 802.1Q tagging).

Option C is wrong because a virtual switch is a Layer 2 device and does not perform IP routing between subnets; routing requires a router or Layer 3 device. Option E is wrong because a virtual switch is a software construct running inside the hypervisor, not a physical device installed in the host.

Exam trap

Cisco often tests the misconception that virtual switches are physical devices or that they perform Layer 3 functions, when in fact they are software-based Layer 2 forwarding engines that support VLANs and uplink connectivity.

89
MCQmedium

A network engineer is configuring Cisco ACI to extend a Layer 2 bridge domain to an external Layer 2 network. The engineer must ensure that the ACI fabric can forward traffic between the bridge domain and the external network without routing. Which ACI construct should be configured to achieve this?

A.Layer 3 Outside (L3Out)
B.Tenant
C.VRF
D.Layer 2 Outside (L2Out)
AnswerD

A Layer 2 Outside (L2Out) is specifically designed to extend a Layer 2 bridge domain to an external Layer 2 network. It allows the ACI fabric to connect to external switches and forward Layer 2 traffic without routing. This is achieved by mapping the bridge domain to an external VLAN on the L2Out. Thus, L2Out is the correct construct for extending a Layer 2 bridge domain to an external Layer 2 network.

Why this answer

To extend a Layer 2 bridge domain to an external Layer 2 network in Cisco ACI, the correct construct is a Layer 2 Outside (L2Out). L2Out maps the bridge domain to an external VLAN and allows Layer 2 traffic to traverse between the fabric and the external switch without routing. Other constructs like L3Out, Tenant, or VRF do not provide this Layer 2 extension capability.

Therefore, L2Out is the correct choice.

Exam trap

The trap here is confusing L2Out with L3Out; L2Out is for Layer 2 extension, while L3Out is for Layer 3 routing to external networks.

90
MCQhard

An engineer is configuring a VXLAN EVPN fabric on Cisco Nexus 9000 switches. VLAN 100 on leaf-1 must be mapped to VNI 10100, and the same Layer 2 segment must extend to leaf-2. The engineer creates VLAN 100 and enters the NVE interface configuration. Which configuration on leaf-1 correctly maps VLAN 100 to VNI 10100 so that the Layer 2 segment can be extended over the VXLAN overlay?

A.interface nve1 / no shutdown / source-interface loopback0 / member vni 10100 / ingress-replication protocol bgp
B.vlan 100 / vn-segment 10100 / interface nve1 / no shutdown / source-interface loopback0 / member vni 10100 / ingress-replication protocol static
C.interface nve1 / no shutdown / source-interface loopback0 / member vni 10100 / vlan 100
D.vlan 100 / vn-segment 10100 / interface nve1 / no shutdown / source-interface loopback0 / member vni 10100
AnswerD

On Nexus 9000, the VLAN-to-VNI binding is created with the vn-segment command under the VLAN configuration, which maps VLAN 100 to VNI 10100. The NVE interface then references that VNI with member vni 10100 and uses loopback0 as the VTEP source. Together these commands correctly encapsulate VLAN 100 traffic and extend the Layer 2 segment to leaf-2.

Why this answer

Extending a VLAN over VXLAN on Nexus 9000 requires two coordinated pieces: the VLAN must be mapped to a VNI using vn-segment under the VLAN, and the NVE interface must include that VNI as a member with a valid source interface. The vn-segment command is what actually binds the Layer 2 segment to the VNI, while the NVE membership enables encapsulation. Omitting either piece leaves VLAN 100 local to leaf-1 and unable to reach leaf-2.

Exam trap

The trap here is believing that adding the VNI under the NVE interface is enough, when the VLAN itself must also be mapped to that VNI with the vn-segment command.

91
MCQmedium

A service provider uses a Cisco ASR 1000 router to provide MPLS L3VPN services to multiple customers. Each customer has their own VRF. Recently, a new customer was added with VRF CUSTOMER_C. After configuration, the customer reports that they can reach some remote sites but not others. The network engineer checks the VRF configuration and finds that the route targets for CUSTOMER_C are correctly configured. The engineer also verifies that BGP sessions to the PE routers are up. The missing routes are from a site that uses a different PE router. Which action should the engineer take to resolve the issue?

A.Increase the MTU on the link between the PE routers.
B.Reconfigure LDP on the PE routers to establish a targeted session.
C.Check the MPLS label stack on the local PE to ensure labels are being swapped correctly.
D.Verify that the route target import/export values on the remote PE match those on the local PE for VRF CUSTOMER_C.
AnswerD

In MPLS Layer 3 VPNs, each VRF is configured with import and export route targets; a received VPNv4 route is installed into a VRF only if its route-target list matches one of the VRF's import targets. If the export RT on the advertising PE does not match the import RT configured in the remote PE for VRF CUSTOMER_C, the route is accepted into the BGP VPNv4 table but silently filtered out of the VRF. Verifying and correcting the RT values to be consistent on both PEs is the requisite fix, as this is the control-plane mechanism responsible for the observed missing route.

Why this answer

The issue is that the remote PE router does not have the correct route target import/export configuration for VRF CUSTOMER_C. In MPLS L3VPN, VRFs on different PEs must have matching route target values to import and export VPNv4 routes into the correct VRF. Even if the local PE is correctly configured, the remote PE must also import the routes from the local PE using the same route target.

Without this, the remote PE will not install the VPNv4 prefixes into its VRF, causing the customer to be unable to reach sites connected to that remote PE.

Exam trap

Cisco often tests the misconception that route target configuration is only needed on one PE, or that BGP session status alone guarantees route exchange, when in fact both import and export RTs must match across all PEs participating in the same VRF.

How to eliminate wrong answers

Option A is wrong because increasing the MTU on the link between PE routers would not affect route reachability; MTU issues typically cause packet fragmentation or drops, not missing routes in a VRF. Option B is wrong because LDP targeted sessions are used for MPLS label distribution between non-adjacent routers, but in this scenario the PE routers are already exchanging BGP VPNv4 routes and LDP is not the mechanism for VRF route import/export. Option C is wrong because checking the MPLS label stack on the local PE would verify label switching, but the problem is that the remote PE does not have the routes in its VRF, not that labels are being swapped incorrectly; label swapping issues would cause forwarding failures, not missing routes in the routing table.

92
MCQeasy

A network engineer is configuring a Cisco Nexus 9000 switch as a VXLAN tunnel endpoint. The engineer needs to define the source IP address used for the VXLAN tunnels and ensure the switch can replicate broadcast, unknown unicast, and multicast traffic. Which configuration element must be created to source the tunnels?

A.A subinterface on the uplink port configured with encapsulation dot1q and used as the NVE source.
B.A tunnel interface configured with tunnel mode gre and the underlay destination as the source.
C.A loopback interface with an IP address that is used as the NVE source in the interface nve1 configuration.
D.A VLAN interface with the same IP address as the underlay physical interface to act as the tunnel source.
AnswerC

The NVE interface on a Nexus 9000 requires a source-interface, typically a loopback, whose IP address becomes the tunnel endpoint. This address must be reachable across the underlay so remote VTEPs can establish VXLAN tunnels. Configuring the loopback and referencing it with the source-interface command under interface nve1 is the standard method to define the tunnel source.

Why this answer

On a Cisco Nexus 9000, the NVE interface is used to define VXLAN tunnel endpoints, and it must reference a source interface, typically a loopback with a stable IP address. That loopback address becomes the VTEP address that remote switches use to build tunnels. The other options describe unrelated interface types or encapsulations that do not fulfill the VXLAN tunnel source requirement.

Exam trap

The trap here is assuming any routed interface can serve as the NVE source, when a stable loopback is the standard and expected choice.

93
MCQhard

A network architect is designing a Cisco SD-Access fabric. The requirement is to provide Layer 3 isolation between different departments while allowing them to share the same physical network. Which Cisco SD-Access component is responsible for providing this isolation?

A.Locator/ID Separation Protocol (LISP)
B.Scalable Group Tag (SGT)
C.Virtual Network (VN)
D.VXLAN Network Identifier (VNI)
AnswerC

In Cisco SD-Access, a Virtual Network (VN) is a logical partition that provides Layer 3 isolation. Each VN is associated with a VRF, and endpoints in different VNs cannot communicate at Layer 3 unless there is a fusion router or external policy. This meets the requirement for department isolation while sharing the physical underlay.

Why this answer

In Cisco SD-Access, Layer 3 isolation between departments is achieved by assigning them to different Virtual Networks (VNs). Each VN is essentially a separate VRF, and the fabric uses VXLAN with distinct VNIs to carry traffic for each VN. This allows the same physical infrastructure to support multiple isolated logical networks.

Exam trap

The trap here is confusing the data plane identifier (VNI) with the logical isolation construct (VN). While a VNI is used to separate traffic in the encapsulation, the actual Layer 3 isolation is provided by the VN's associated VRF.

← PreviousPage 2 of 2 · 93 questions total

Ready to test yourself?

Try a timed practice session using only Virtualization questions.