easyMultiple Choice
350-401 Practice Question: Deploying a virtual WAN optimizer (vWAAS) on a…
A company is deploying a virtual WAN optimizer (vWAAS) on a Cisco NFVIS host. The engineer needs to ensure that the vWAAS can intercept traffic between two VNFs running on the same host. The traffic currently flows directly between the VNFs without passing through the vWAAS. What should the engineer configure to redirect the traffic?
⚠ Common exam trap
Watch out — candidates often assume traffic redirection between VNFs must be done at Layer 3 (routing) using static routes or PBR, but Cisco tests the understanding that NFVIS service chaining operates at Layer 2 within the hypervisor, providing transparent interception without modifying the VNFs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a service chain in NFVIS that places the vWAAS between the two VNFs.
NFVIS supports service chaining, which allows an administrator to define a sequence of VNFs that traffic must traverse. By creating a service chain that places the vWAAS between the two VNFs, NFVIS will automatically redirect the traffic through the vWAAS using internal bridging or vSwitch forwarding rules, without requiring any configuration changes on the VNFs themselves.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create a service chain in NFVIS that places the vWAAS between the two VNFs.
Why this is correct
In NFVIS, service chaining defines an ordered data path that steers traffic through a sequence of VNFs at the virtual switch level, so placing the vWAAS between the two VNFs ensures it inspects and optimizes traffic without requiring any routing changes inside the VNFs themselves. This is the native, supported method because NFVIS uses service chain rules to redirect traffic between the VNF's virtual interfaces, making the vWAAS operate as an inline service node. Configuring routes or policies on the VNFs would not provide the same guaranteed, ordered traffic steering and would be operationally cumbersome.
- ✗
Configure a static route on each VNF pointing to the vWAAS.
Why it's wrong here
Pointing a static route on each VNF to the vWAAS would only affect traffic that the VNFs explicitly route to the vWAAS's IP address; it would not intercept the transit traffic flowing directly between the two VNFs if they are connected to the same NFVIS virtual switch at Layer 2. Static routes also assume the vWAAS is a Layer 3 next hop, but the vWAAS is designed as an inline transparent service rather than a router. Without a service chain, the VNFs' data-plane traffic will bypass the vWAAS entirely because the virtual switch forwards frames directly between the VNF interfaces.
- ✗
Enable WCCP on the vWAAS and configure the VNFs to use WCCP.
Why it's wrong here
WCCP (Web Cache Communication Protocol) is an IP-based protocol used by routers and switches to redirect traffic to a cache or service engine, typically for web caching or WAN optimization; it is not designed to redirect traffic between VNFs within the same NFVIS host. The VNFs would need to be WCCP-enabled routers, and the vWAAS would have to act as a WCCP client, which is not the standard deployment model for vWAAS in an NFVIS service chain. Moreover, WCCP operates at the network layer and does not provide the same integrated, host-local traffic steering that NFVIS service chaining offers natively.
- ✗
Use policy-based routing on the VNFs to forward traffic to the vWAAS.
Why it's wrong here
Policy-based routing (PBR) on each VNF requires manual route-map configuration and a reachable next-hop address for the vWAAS, which adds complexity and is prone to configuration drift across multiple VNFs. More importantly, PBR only applies to traffic that matches the defined policy and is local to each VNF; it does not provide the centralized, ordered, and bidirectional service chaining that NFVIS offers. Using PBR bypasses the NFVIS service graph, so the vWAAS would not be automatically inserted into the data path, and the solution would not scale or guarantee consistent traffic steering across all VNFs.
Go deeper
Related to this question
Learn chapter
EIGRP: Basics and Advanced Configuration
Key term
Virtual Switch
A virtual switch is a software-based network switch that connects virtual machines within a hypervisor and forwards traffic between them and the physical network.
Key term
Virtual Machine Networking
Virtual machine networking is how virtual computers on a physical server connect to each other, to the internet, and to the rest of a network.
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.