Courseiva
mediumMultiple Choice

350-401 Practice Question: A company uses Cisco NFVIS to host a virtual ASA…

A company uses Cisco NFVIS to host a virtual ASA (vASA) and a virtual router (vRouter). The engineer notices that the vASA cannot communicate with the vRouter even though both are on the same NFVIS host. The vASA is connected to a bridge network, and the vRouter is connected to a different bridge. What should the engineer do to enable communication between the two VNFs?

⚠ Common exam trap

Cisco often tests the misconception that VLAN tagging alone can connect VNFs across different bridges, but VLANs only segment traffic within a single bridge and do not create connectivity between separate bridges.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a new bridge that connects both VNFs, or use a virtual switch to route between the bridges.

In NFVIS, VNFs attached to different bridge networks are isolated at Layer 2. To enable communication between them, you must either create a new bridge that connects both VNFs or use a virtual switch (e.g., a Linux bridge with routing enabled) to forward traffic between the two bridges. This allows the VNFs to share a common Layer 2 domain or have a routed path through the hypervisor.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Connect a physical cable between two ports on the NFVIS host.

    Why it's wrong here

    Incorrect. NFVIS is a virtualization platform where VNFs are software instances running as virtual machines or containers. Their vNICs are connected to virtual bridges or virtual switches inside the host, not to physical ports. A physical cable between two host ports would only create an external loop and would not provide a data path between the VNFs' virtual interfaces; it also wastes physical ports and introduces unnecessary latency.

  • ✓

    Create a new bridge that connects both VNFs, or use a virtual switch to route between the bridges.

    Why this is correct

    Correct. In NFVIS, you can create a Linux bridge that acts as a virtual Layer 2 switch. Attaching both VNFs' vNICs to the same bridge places them in the same broadcast domain, allowing direct communication via MAC learning and forwarding. Alternatively, if the VNFs reside on different bridges (separate Layer 2 domains), you can use a virtual router—either a VNF configured for routing or NFVIS's own virtual switch—to route packets between those bridges. This is the standard method for inter-VNF connectivity on a single NFVIS host.

  • ✗

    Configure VLAN tagging on both VNFs with the same VLAN ID.

    Why it's wrong here

    Incorrect. VLAN tagging is a method of segmenting traffic within a shared Layer 2 infrastructure, not a mechanism to join separate bridges. Even if both VNFs are configured with the same VLAN ID, they will remain isolated if their interfaces are attached to different bridges, because each bridge is an independent Layer 2 domain. For VLAN tagging to enable connectivity, the VNFs must already be on a common trunk or share a bridge that carries that VLAN; merely matching VLAN IDs does not create a data path between disjoint bridges.

  • ✗

    Add a static route on each VNF pointing to the other VNF's IP address.

    Why it's wrong here

    Incorrect. Static routes are control-plane entries that tell a device where to send packets, but they rely on an existing Layer 2 data path to reach the next hop. If the two VNFs are on different bridges, they have no direct Layer 2 adjacency, and the static route's next-hop IP would be unreachable because there is no connected interface on a common subnet. You first need to connect the bridges via a router or place the VNFs on the same bridge; only then can static routes (or dynamic routing) successfully forward traffic between them.

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.