Courseiva
mediumMultiple Choice

350-401 Practice Question: A service provider is deploying NFV to offer…

A service provider is deploying NFV to offer managed SD-WAN services to enterprise customers. The architect must place virtual network functions (VNFs) such as vEdge routers and firewalls in the provider's data center. Which VNF placement model allows the provider to chain these functions efficiently and scale per customer?

⚠ Common exam trap

Cisco often tests the misconception that placing all VNFs on a single host (Option A) is simpler and efficient, but the trap is that this violates NFV's high-availability and multi-tenant scaling requirements, which are core to service provider SD-WAN offerings.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use a centralized service chain with a service graph that defines the order of VNFs, and deploy VNFs on separate hosts for redundancy.

A centralized service chain with a service graph allows the provider to define the ordered sequence of VNFs (e.g., vEdge router then firewall) and deploy them on separate hosts for redundancy. This model aligns with NFV MANO (Management and Orchestration) principles, enabling efficient scaling per customer by instantiating VNFs as needed while maintaining the service chain across hypervisors.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Place all VNFs for a customer on a single hypervisor host and use internal virtual switches to chain them.

    Why it's wrong here

    Consolidating every VNF for a customer on one hypervisor host and relying on intra-host virtual switches reduces east-west latency but eliminates any meaningful redundancy. A single host failure or a hypervisor software bug tears down the entire service chain, and the approach does not allow elastic scaling across multiple hosts for changing customer traffic. It also creates a hard coupling of compute, storage, and networking resources for that tenant, making maintenance or host evacuation disruptive.

  • ✓

    Use a centralized service chain with a service graph that defines the order of VNFs, and deploy VNFs on separate hosts for redundancy.

    Why this is correct

    A centralized service chain driven by a service graph is the correct architecture because the graph explicitly models the ordered sequence of VNFs (e.g., firewall then WAN optimizer) independent of their physical placement. The SD-WAN controller can then program edge routers to steer traffic through the chain while orchestrators deploy VNFs on separate hosts to achieve high availability, failover, and per-customer customization. This separates the logical service policy from the underlying compute infrastructure, allowing the chain to be scaled horizontally and replayed across redundant hosts without reengineering the policy.

  • ✗

    Deploy each VNF as a separate virtual machine on a dedicated physical server to maximize performance.

    Why it's wrong here

    Assigning a dedicated physical server to each VNF ignores the very purpose of virtualization and NFV: agility, elasticity, and hardware-independent lifecycle management. This model significantly increases capital and operational expense because every customer's firewall and routing function consumes its own bare-metal resources, and any hardware failure requires a physical replacement rather than a simple restart on another host. It also prevents dynamic scaling and makes it impractical to insert new VNFs into an existing chain because the chain's topology becomes tied to static server placement.

  • ✗

    Use a single VNF that combines routing and firewall functions to avoid chaining complexity.

    Why it's wrong here

    Collapsing routing and firewall into a single monolithic VNF avoids the control-plane complexity of chaining but sacrifices modularity and policy granularity. It forces every customer to use the same security posture and routing policies, making it impossible to enforce separate security zones or insert additional functions (such as IDS or WAN optimization) into the path. Moreover, such a combined virtual appliance must be upgraded and scaled as one unit, creating vendor lock-in and reducing the ability to combine best-of-breed functions from different vendors.

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.