Courseiva
mediumMultiple Choice

350-401 Practice Question: An engineer is deploying a Linux virtual machine…

An engineer is deploying a Linux virtual machine on a KVM hypervisor. The VM needs to be connected to a virtual network that provides isolation from other VMs on the same host but allows communication with the host and external networks. The engineer creates a Linux bridge and attaches the VM's tap interface to it. However, the VM cannot reach the external network. The host has a physical NIC (eth0) connected to the corporate network. What is the missing configuration step?

⚠ Common exam trap

It's easy for candidates to confuse bridging with NAT or routing, assuming that IP forwarding or NAT is required for external access, when in fact a bridged setup simply needs the physical NIC as a bridge port to extend Layer 2 connectivity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Add the physical NIC (eth0) as a port to the Linux bridge.

A Linux bridge acts like a virtual switch. To allow the VM to reach the external network, the physical NIC (eth0) must be added as a port to the bridge. This bridges the VM's tap interface with the host's physical network, enabling Layer 2 connectivity to the corporate network and upstream routing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Add the physical NIC (eth0) as a port to the Linux bridge.

    Why this is correct

    The bridge must include a physical uplink port (eth0) to serve as a switching fabric between VMs and the external network. Without eth0 as a port, the bridge is an isolated Layer 2 domain where frames can only reach other VMs or the host itself; nothing is forwarded beyond. Adding eth0 to the bridge (e.g., with 'ip link set eth0 master br0') makes the bridge act like a virtual switch with a trunk/access port to the physical LAN, allowing VM traffic to reach the gateway and other hosts directly.

  • ✗

    Configure a default gateway on the VM's network interface.

    Why it's wrong here

    Setting a default gateway on the VM’s interface is a Layer 3 routing configuration. Even if the VM has a correct default gateway (typically the LAN router), the VM’s Ethernet frames carrying those packets are sent to the MAC address of that gateway through the virtual switch. If the Linux bridge has no physical NIC as an uplink, those frames never leave the host, so the gateway is unreachable. Thus, this is a routing-level fix that cannot compensate for the missing bridge uplink.

  • ✗

    Assign an IP address to the Linux bridge interface.

    Why it's wrong here

    Assigning an IP address to the bridge interface (e.g., br0) configures Layer 3 connectivity for the host itself on that bridge. This allows the host to communicate with VMs attached to the bridge, but it does not connect the bridge to external networks. Traffic from a VM destined beyond the host would still need a Layer 2 path to the physical NIC; an IP on the bridge provides no such path because bridging operates at Layer 2, independent of IP addresses.

  • ✗

    Enable IP forwarding and configure NAT on the host.

    Why it's wrong here

    Enabling IP forwarding and configuring NAT would create a routed network using the host as a router, where VMs’ packets are rewritten and forwarded out through the host's physical interface. This is a different architecture than transparent bridging and would require an additional subnet for the VMs, plus NAT rules. In a bridged setup, this is both unnecessary and undesirable because it breaks the VM’s direct presence on the physical LAN. Furthermore, without eth0 added to the bridge, forwarding alone cannot move frames from br0 out to the physical network because the bridge has no egress port.

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.