Courseiva
mediumMultiple Choice

350-401 Practice Question: Deploying a multi-tenant data center using VMware…

A company is deploying a multi-tenant data center using VMware vSphere. The architect must ensure that each tenant’s virtual machines (VMs) are isolated at Layer 2 while sharing the same physical NICs. Which design approach best meets this requirement?

⚠ Common exam trap

A common mix-up: candidates confuse VLAN trunking (which carries multiple VLANs on a single link) with port group assignment, mistakenly thinking that placing all VMs in the same port group with trunking provides isolation, when in fact it collapses all tenants into a single broadcast domain.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure a single standard virtual switch and assign each VM to a separate port group with unique VLAN IDs.

Configuring a standard virtual switch with separate port groups and unique VLAN IDs provides Layer 2 isolation between tenants by leveraging 802.1Q VLAN tagging. Each VM’s traffic is tagged with its assigned VLAN ID, ensuring that VMs in different port groups cannot communicate directly at Layer 2, even though they share the same physical NICs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Configure a single standard virtual switch and assign each VM to a separate port group with unique VLAN IDs.

    Why this is correct

    Configuring a single standard virtual switch with separate port groups for each VM and assigning unique VLAN IDs isolates traffic at Layer 2 by ensuring that frames from one VM are tagged with its designated VLAN and cannot be forwarded to a VM in a different VLAN segment, as the virtual switch enforces VLAN boundaries at the virtual port level. This approach allows all tenants to share the same physical NIC(s) while keeping broadcast, multicast, and unicast traffic constrained to the assigned VLAN, meeting the isolation requirement without additional hardware.

  • ✗

    Deploy a separate physical NIC for each tenant and bridge them to the VMs.

    Why it's wrong here

    Deploying a separate physical NIC for each tenant and bridging these NICs to the VMs eliminates the virtualization benefits of shared uplinks, as each tenant consumes a dedicated physical port, making the design costly and incapable of scaling beyond a few tenants. Furthermore, a bridge on its own does not provide Layer 2 isolation; without VLAN segmentation or filtering rules, a bridged NIC can still forward traffic between connected VMs, so this approach does not reliably meet the isolation requirement.

  • ✗

    Use a distributed virtual switch with VLAN trunking and assign all VMs to the same port group.

    Why it's wrong here

    On a distributed virtual switch, enabling VLAN trunking on the uplink only allows multiple VLANs to traverse the same physical link; it does not, by itself, segment traffic between VMs. Assigning all VMs to the same port group means that every VM is a member of the same logical network segment, so frames are forwarded uncapped across all hosts and tenants, breaking isolation completely. Trunking is useful when different port groups use different VLAN IDs, but here it simply connects all VMs to the same VLAN, providing no security boundary.

  • ✗

    Enable promiscuous mode on the virtual switch to allow all VMs to see each other’s traffic.

    Why it's wrong here

    Enabling promiscuous mode on a virtual switch or port group instructs the hypervisor to deliver all frames seen on that virtual switch to the guest NIC, regardless of the destination MAC address, so any VM in that port group can capture traffic intended for other VMs. This is the antithesis of isolation: instead of preventing cross-tenant access, it actively enables eavesdropping and lateral traffic inspection, creating a severe security vulnerability in a multi-tenant environment. Therefore, it is never a valid technique for achieving isolation.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.