mediumMultiple Choice
350-401 Practice Question: A service provider is deploying NFV to host…
A service provider is deploying NFV to host virtual network functions (VNFs) such as firewalls, routers, and WAN optimizers on a single server. The design must support service chaining, where traffic flows through multiple VNFs in a specific order, and must allow dynamic insertion of new VNFs without re-cabling. Which technology should be used to implement the service chain?
⚠ Common exam trap
Test-takers frequently confuse VLAN trunking (Option A) as sufficient for service chaining, but VLANs only provide segmentation, not the policy-based traffic steering required to enforce a specific ordered sequence of VNFs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
VXLAN overlay with policy-based forwarding to direct traffic through VNFs
VXLAN overlay with policy-based forwarding (PBF) is the correct choice because it enables service chaining by encapsulating traffic and steering it through a sequence of VNFs based on policies, without requiring physical re-cabling. This allows dynamic insertion of new VNFs by simply updating the forwarding policies in the overlay, which is essential for NFV environments where VNFs are hosted on the same server and must be chained flexibly.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
VLAN trunking between VNFs on the same hypervisor
Why it's wrong here
VLAN trunking is limited to Layer 2 and typically bound to a single subnet or broadcast domain, so it cannot natively scale to dynamic service chains across multiple VNFs. Any modification to the VNF sequence requires manual VLAN or interface reconfiguration, and the 4096 VLAN limit plus the lack of policy-based steering make it impractical for agile NFV environments.
- ✓
VXLAN overlay with policy-based forwarding to direct traffic through VNFs
Why this is correct
VXLAN overlay with policy-based forwarding is the correct approach because it uses VXLAN Network Identifiers (VNIs) to create scalable, isolated tunnels that can span the hypervisor without physical topology constraints. Traffic can be steered through a desired sequence of VNFs by applying policies based on packet attributes or VNI, allowing seamless insertion, removal, or reordering of VNFs without reconfiguring the underlying network.
- ✗
Static routing between VNFs using dedicated interfaces
Why it's wrong here
Static routing between VNFs using dedicated interfaces requires manual configuration of each route and interface binding, making it completely inflexible for dynamic service chaining. Any change in the VNF order or addition of a new VNF forces an administrator to update routes throughout the path, and dedicated interfaces do not support policy-based selection of traffic classes, so this approach cannot adapt to evolving NFV workloads.
- ✗
MPLS L3VPN between VNFs
Why it's wrong here
MPLS L3VPN is designed for WAN connectivity between sites, not for service chaining among VNFs running on the same hypervisor. Implementing it locally would require complex label switching and VPN routing tables that are unnecessary for intra-host traffic steering, and it lacks the granular, policy-driven flow redirection needed to dynamically sequence VNFs in an NFV service chain.
Go deeper
Related to this question
Key term
Fabric Fundamentals
Fabric Fundamentals is the set of core concepts behind a network fabric, where switches and routers form a single logical system that simplifies traffic forwarding and automation.
Key term
VXLAN
VXLAN is a network overlay technology that encapsulates Layer 2 Ethernet frames in UDP packets to extend VLANs across Layer 3 networks.
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.