mediumMultiple Choice
350-401 Practice Question: An enterprise is migrating its data center to a…
An enterprise is migrating its data center to a leaf-spine architecture to support high east-west traffic between servers. The design must provide non-blocking forwarding and allow for easy scaling by adding more spines. Which characteristic is essential for the spine switches in this design?
⚠ Common exam trap
Cisco often tests the misconception that STP is needed in all redundant switch designs, but in a Layer 3 leaf-spine architecture, STP is not used because routing protocols inherently prevent loops and allow all links to be active.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Spine switches must support high port density and high forwarding capacity, and act as Layer 3 routers
In a leaf-spine architecture designed for non-blocking forwarding and high east-west traffic, spine switches must act as Layer 3 routers with high port density and forwarding capacity. This allows them to perform Equal-Cost Multi-Path (ECMP) routing, which distributes traffic across all available uplinks without blocking, ensuring that any leaf can reach any other leaf with predictable latency and full bandwidth utilization.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Spine switches must run Spanning Tree Protocol (STP) to prevent loops
Why it's wrong here
Leaf-spine fabrics are built as a Layer 3 routed network; each leaf-to-spine link is a routed point-to-point interface, so there are no Layer 2 loops to guard against. Running STP would actively block the redundant parallel uplinks that are supposed to carry traffic via ECMP, eliminating load balancing and reducing fault tolerance. STP's blocking state also introduces unnecessary convergence delays, making it completely unsuitable for a modern data center fabric.
- ✓
Spine switches must support high port density and high forwarding capacity, and act as Layer 3 routers
Why this is correct
The spine layer is the fabric's core, aggregating all leaf switches, so it must have high port density to terminate connections from every leaf, and high forwarding capacity (throughput and packet-per-second) to handle the aggregate east-west traffic without oversubscription. As a Layer 3 router, each spine forwards IP packets between subnets using the routing table, not MAC addresses, and leverages Equal-Cost Multipath (ECMP) to spread flows across all available leaf links. This makes the spine the critical scale and performance bottleneck in the design.
- ✗
Spine switches must be connected to each other to provide redundancy
Why it's wrong here
Spine switches are deliberately not connected to each other; doing so would introduce Layer 3 routing adjacencies that could cause suboptimal paths and potential loops in the routing protocol. Redundancy in a leaf-spine fabric comes from having multiple independent spines, with every leaf connected to every spine, so if one spine fails, traffic simply uses the remaining spines. Interconnecting spines would add extra hops, increase latency, and provide no added leaf-to-leaf connectivity, since all leaf traffic already transits a single spine hop.
- ✗
Spine switches must perform NAT to translate between VLANs
Why it's wrong here
Network Address Translation (NAT) is an edge function for translating between private and public address spaces, not a requirement for inter-VLAN communication, which in a leaf-spine fabric is handled by Layer 3 routing on the spines or leaves using SVIs. Applying NAT inside the fabric would break the end-to-end IP model, add per-flow state, and create a single point of failure and complexity, undermining the stateless, scale-out nature of the design. Inter-VLAN routing simply requires a default gateway on the Layer 3 switch, not NAT.
Visual reference
Go deeper
Related to this question
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.