mediumMultiple Choice
350-401 Practice Question: Deploying a multi-tenant data center using VMware…
A company is deploying a multi-tenant data center using VMware vSphere. The architect must ensure that each tenant’s virtual machines (VMs) are isolated at Layer 2 while sharing the same physical NICs. Which design approach best meets this requirement?
⚠ Common exam trap
A common mix-up: candidates confuse VLAN trunking (which carries multiple VLANs on a single link) with port group assignment, mistakenly thinking that placing all VMs in the same port group with trunking provides isolation, when in fact it collapses all tenants into a single broadcast domain.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure a single standard virtual switch and assign each VM to a separate port group with unique VLAN IDs.
Configuring a standard virtual switch with separate port groups and unique VLAN IDs provides Layer 2 isolation between tenants by leveraging 802.1Q VLAN tagging. Each VM’s traffic is tagged with its assigned VLAN ID, ensuring that VMs in different port groups cannot communicate directly at Layer 2, even though they share the same physical NICs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure a single standard virtual switch and assign each VM to a separate port group with unique VLAN IDs.
Why this is correct
Configuring a single standard virtual switch with separate port groups for each VM and assigning unique VLAN IDs isolates traffic at Layer 2 by ensuring that frames from one VM are tagged with its designated VLAN and cannot be forwarded to a VM in a different VLAN segment, as the virtual switch enforces VLAN boundaries at the virtual port level. This approach allows all tenants to share the same physical NIC(s) while keeping broadcast, multicast, and unicast traffic constrained to the assigned VLAN, meeting the isolation requirement without additional hardware.
- ✗
Deploy a separate physical NIC for each tenant and bridge them to the VMs.
Why it's wrong here
Deploying a separate physical NIC for each tenant and bridging these NICs to the VMs eliminates the virtualization benefits of shared uplinks, as each tenant consumes a dedicated physical port, making the design costly and incapable of scaling beyond a few tenants. Furthermore, a bridge on its own does not provide Layer 2 isolation; without VLAN segmentation or filtering rules, a bridged NIC can still forward traffic between connected VMs, so this approach does not reliably meet the isolation requirement.
- ✗
Use a distributed virtual switch with VLAN trunking and assign all VMs to the same port group.
Why it's wrong here
On a distributed virtual switch, enabling VLAN trunking on the uplink only allows multiple VLANs to traverse the same physical link; it does not, by itself, segment traffic between VMs. Assigning all VMs to the same port group means that every VM is a member of the same logical network segment, so frames are forwarded uncapped across all hosts and tenants, breaking isolation completely. Trunking is useful when different port groups use different VLAN IDs, but here it simply connects all VMs to the same VLAN, providing no security boundary.
- ✗
Enable promiscuous mode on the virtual switch to allow all VMs to see each other’s traffic.
Why it's wrong here
Enabling promiscuous mode on a virtual switch or port group instructs the hypervisor to deliver all frames seen on that virtual switch to the guest NIC, regardless of the destination MAC address, so any VM in that port group can capture traffic intended for other VMs. This is the antithesis of isolation: instead of preventing cross-tenant access, it actively enables eavesdropping and lateral traffic inspection, creating a severe security vulnerability in a multi-tenant environment. Therefore, it is never a valid technique for achieving isolation.
Visual reference
Go deeper
Related to this question
Key term
VLAN Trunking
VLAN Trunking is a method to carry traffic for multiple VLANs over a single network link between switches or between a switch and a router.
Key term
Virtual Switch
A virtual switch is a software-based network switch that connects virtual machines within a hypervisor and forwards traffic between them and the physical network.
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.