Courseiva
hardMultiple Choice

350-401 Practice Question: An enterprise is deploying a virtualized network…

An enterprise is deploying a virtualized network function (VNF) for a next-generation firewall on a KVM-based hypervisor. The architect must ensure that the VNF can handle high throughput without CPU bottlenecks. Which hypervisor configuration technique should the architect use to dedicate physical CPU cores to the VNF?

⚠ Common exam trap

Cisco often tests the misconception that simply increasing vCPU count (Option D) or enabling overcommitment (Option A) can solve performance issues, when in reality, dedicated core assignment via pinning is required for deterministic VNF throughput.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure NUMA pinning and CPU pinning to dedicate physical cores to the VNF's virtual CPUs.

CPU pinning (also called CPU affinity) binds specific virtual CPUs (vCPUs) of the VNF to dedicated physical CPU cores, eliminating context-switching overhead and ensuring deterministic performance. NUMA pinning further aligns vCPUs and memory with the same Non-Uniform Memory Access node, reducing latency. This configuration is critical for VNFs like next-generation firewalls that require high throughput and low jitter.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable CPU overcommitment to allow the VNF to use any available CPU cycles.

    Why it's wrong here

    Enabling CPU overcommitment lets the hypervisor schedule multiple vCPUs on shared physical cores, which can cause unpredictable latency and throughput because a VNF's packets may stall behind other tenants' workloads. High-throughput SD-WAN VNFs require deterministic, line-rate processing, so this lack of guaranteed CPU capacity directly violates the strict performance SLA. Additionally, overcommitment can disrupt NUMA locality and cache residency, degrading forwarding performance further. Therefore, while overcommitment maximizes host utilization, it is an inappropriate performance strategy for production VNFs.

  • ✓

    Configure NUMA pinning and CPU pinning to dedicate physical cores to the VNF's virtual CPUs.

    Why this is correct

    Configuring NUMA pinning and CPU pinning dedicates physical CPU cores and ensures their memory is allocated on the same NUMA node, giving the VNF exclusive, non-overlapping access to compute resources. In KVM, NUMA pinning binds each virtual CPU to a specific host core and the VM’s memory to a local NUMA node, avoiding expensive remote memory accesses and eliminating hypervisor scheduler contention. This deterministic resource allocation is essential for high-throughput SD-WAN VNFs, which need stable forward rates and low jitter under load. It is the recommended NFV performance practice over any other tuning option.

  • ✗

    Use VMware vSphere instead of KVM for better VNF performance.

    Why it's wrong here

    Switching from KVM to VMware vSphere would not address the underlying issue because the question specifically asks how to optimise a KVM-based VNF, and both hypervisors support CPU and NUMA pinning techniques. The real bottleneck is the lack of dedicated, non-overcommitted CPU resources, not the hypervisor vendor; without pinning, even vSphere would expose the VNF to scheduler contention and remote memory latency. In an SD-WAN edge NFV platform, the chosen hypervisor is often fixed by the vendor, and replacing it introduces operational complexity without guaranteeing performance gains. Therefore, the correct action is to tune KVM’s pinning features rather than change hypervisors.

  • ✗

    Increase the number of virtual CPUs assigned to the VNF to improve throughput.

    Why it's wrong here

    Simply increasing the number of virtual CPUs assigned to a VNF usually fails to improve throughput because packet-processing workloads are often pinned to specific queue/interrupt cores, and extra vCPUs may all contend for the same physical cores unless pinning is configured. Adding vCPUs without pinning increases scheduler activity, cache thrashing, and context switching, which can actually degrade forwarding performance and introduce jitter. Throughput in NFV depends more on deterministic core allocation, memory locality, and I/O efficiency than on raw vCPU count. So merely enlarging the vCPU pool ignores the real cause of poor performance and can make things worse.

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.