350-401 Virtualization Practice Question
Which TWO statements about virtual switching in a hypervisor environment are correct?
⚠ Common exam trap
Cisco often tests the misconception that virtual switches are physical devices or that they perform Layer 3 functions, when in fact they are software-based Layer 2 forwarding engines that support VLANs and uplink connectivity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A virtual switch can be connected to a physical network through uplink ports.
Option A is correct because a virtual switch (vSwitch) uses uplink ports, also called physical NICs or pNICs, to bridge virtual machine traffic onto the physical network, allowing VMs to communicate beyond the host. Option D is correct because a virtual switch operates at Layer 2, learning MAC addresses and forwarding Ethernet frames between virtual machines (and to uplinks) based on destination MAC addresses, just like a physical switch. Option B is wrong because virtual switches do support VLAN tagging, typically via VLAN IDs on port groups or virtual switch ports (e.g., 802.1Q tagging). Option C is wrong because a virtual switch is a Layer 2 device and does not perform IP routing between subnets; routing requires a router or Layer 3 device. Option E is wrong because a virtual switch is a software construct running inside the hypervisor, not a physical device installed in the host.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A virtual switch can be connected to a physical network through uplink ports.
Why this is correct
Uplink ports bind a virtual switch to physical NICs, bridging guest VM traffic onto the wired network. This satisfies the stem's requirement for correct virtual switching statements, since without uplinks, VMs on the vSwitch could only communicate internally, isolated from the physical infrastructure.
- ✗
A virtual switch does not support VLAN tagging.
Why it's wrong here
Virtual switches do support VLAN tagging: they can trunk 802.1Q tags to the physical uplink and enforce VLAN membership per port group. It is tempting because standard vSwitches historically lacked advanced features, but VLAN tagging is a core capability in vSphere and Hyper-V virtual switching.
- ✗
A virtual switch performs routing between different subnets.
Why it's wrong here
Virtual switches operate at Layer 2, forwarding Ethernet frames by MAC address; they do not perform Layer 3 routing between subnets. Routing is handled by a router or a Layer 3 switch, which would be correct if the scenario required inter-subnet traffic.
- ✓
A virtual switch forwards frames between virtual machines based on MAC addresses.
Why this is correct
A hypervisor virtual switch operates at Layer 2, learning source MAC addresses and forwarding frames only to the port where the destination MAC resides, exactly as a physical switch does. This satisfies the requirement to move traffic between virtual machines on the same host without routing.
- ✗
A virtual switch is a physical device installed in the hypervisor host.
Why it's wrong here
A virtual switch is software inside the hypervisor, not a physical device; it forwards frames between virtual NICs and uplinks. Physical switches are the hardware counterpart, and would be the answer if the question asked about connecting hypervisor hosts to the access layer.
Visual reference
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
Learn chapter
Spine-Leaf and Software-Defined Network Architectures
Key term
Virtual Machine Networking
Virtual machine networking is how virtual computers on a physical server connect to each other, to the internet, and to the rest of a network.
Key term
Virtual Switch
A virtual switch is a software-based network switch that connects virtual machines within a hypervisor and forwards traffic between them and the physical network.
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.