Key details for this exam, checked against the published exam outline
Each question shows the correct answer and an explanation of why it is right
Which of the following statements about MAC mobility is TRUE?
Comprehensive and Detailed 150 to 250 words of Explanation From [SR Linux EVPN and Data Center Interconnect/Course Guide/topics]:
MAC mobility is the EVPN mechanism used when a host MAC moves from one PE to another. The control plane uses a MAC Mobility extended community and sequence number behavior to determine the most recent valid location for the MAC. When a PE locally learns a MAC that was previously learned through EVPN, it advertises the MAC with an incremented sequence number, allowing remote PEs to prefer the newer location. Therefore, option B is wrong because the sequence number is not decremented. Option A is also wrong because the original PE does not advertise the locally learned MAC with a maximum sequence value as a normal mobility procedure. Option D is inaccurate because PEs do not need direct MAC table synchronization; they rely on EVPN control-plane advertisements and withdrawals. The true statement is option C: the originating PE generates a withdraw message after the same locally learned MAC ages out. This withdrawal removes stale reachability from remote PEs and prevents continued forwarding toward a PE that no longer has the host locally attached. Reference: EVPN MAC mobility, sequence-number handling, MAC route withdrawal after aging.
Which of the following statements about utilizing asymmetric routing in an L3 EVPN network is FALSE?
Comprehensive and Detailed 150 to 250 words of Explanation From [SR Linux EVPN and Data Center Interconnect/Course Guide/topics]:
Asymmetric routing relies heavily on host MAC/IP information because the ingress PE performs routing into the destination subnet and then sends the frame across the overlay using the destination MAC-VRF/VNI. This means PEs require enough ARP and MAC/IP binding information to forward traffic toward remote hosts correctly. If a host has multiple IP addresses on the same interface, separate EVPN route type 2 advertisements may be needed to communicate each IP-to-MAC binding. The ingress and egress PEs participate in MAC and IP forwarding across the end-to-end service path, but the forwarding responsibilities differ by direction and stage. The false statement is option C. The statement says all MAC-VRFs connected to the L3 EVPN network must exist on each PE, but that is not the correct requirement in this question's verified answer set. In practical EVPN designs, the exact MAC-VRF placement depends on whether the service is implemented as asymmetric, symmetric, interface-less, or interface-ful routing. Here, the course answer marks the universal MAC-VRF requirement as false. Reference: asymmetric L3 EVPN routing, RT-2 MAC/IP advertisements, ARP and MAC forwarding behavior.
Which of the following statements about EVPN PE-CE routing, using BGP as the routing protocol, is FALSE?
Comprehensive and Detailed 150 to 250 words of Explanation From [SR Linux EVPN and Data Center Interconnect/Course Guide/topics]:
In EVPN PE-CE routing, the PE exchanges ordinary IPv4 or IPv6 unicast routing information with the CE. When the PE learns CE prefixes, it imports them into the tenant IP-VRF and advertises them to other EVPN PEs as EVPN route type 5 IP Prefix routes. Conversely, when the PE receives EVPN routes from remote PEs, it can advertise corresponding IPv4/IPv6 BGP updates toward the CE, subject to policy. Import and export policies are essential because they control which customer routes are accepted, which EVPN-learned routes are advertised, and how attributes are modified. Option C is false because iBGP is not the preferred PE-CE model in this context. eBGP is typically preferred between PE and CE because it creates a clean administrative routing boundary between the provider/data-center edge and the customer or external router. Using eBGP also simplifies route policy, loop prevention, and operational separation. The CE does not need to participate in the EVPN overlay; it speaks standard BGP unicast with the PE, while the PE performs the EVPN RT-5 advertisement into the fabric. Reference: EVPN PE-CE BGP routing, eBGP preference, RT-5 prefix advertisement, import/export policy.
Which of the following statements about a distributed Layer 2 EVPN is FALSE?
Comprehensive and Detailed 150 to 250 words of Explanation From [SR Linux EVPN and Data Center Interconnect/Course Guide/topics]:
In a distributed Layer 2 EVPN service, the local leaf learns host reachability from frames received on access interfaces. When a host replies to an ARP request, the local leaf can learn the source MAC address from the Ethernet frame and install it in the MAC forwarding table. If the ARP payload contains an IP/MAC binding, the PE can also use that information for proxy ARP and EVPN MAC/IP advertisement. The local PE then advertises the learned endpoint reachability using EVPN route type 2 to its BGP EVPN peers or route reflector. The false statement is B. The ARP reply is not replicated to every leaf in the flooding list as a normal operation. EVPN's purpose is to reduce unnecessary flooding by distributing endpoint reachability through the control plane. BUM replication is used for broadcast, unknown unicast, and multicast traffic when needed, but a learned ARP reply does not require blind replication to all remote leaves. Instead, the leaf advertises the learned MAC/IP state through MP-BGP EVPN, allowing remote PEs to install accurate forwarding and proxy ARP state. Reference: distributed L2 EVPN operation, ARP learning, EVPN RT-2 advertisement.
Leaf routers are configured to support Layer 2 multi-homing all-active mode.
Which of the following statements is FALSE?
Comprehensive and Detailed 150 to 250 words of Explanation From [SR Linux EVPN and Data Center Interconnect/Course Guide/topics]:
In all-active Layer 2 EVPN multi-homing, the host is typically dual-homed to two or more leaf routers using a LAG. The participating leaf routers must configure the LAG and associate it with the Ethernet Segment so EVPN can advertise the common ESI and apply aliasing, split-horizon, and DF procedures. If VLAN tagging is used for service separation, tagging must be configured on the LAG interface so that the correct subinterfaces can bind into the MAC-VRF and Ethernet Segment. Option C is false because it states that the LACP system-id-mac must uniquely identify each leaf router. In an all-active EVPN multihomed LAG, the opposite principle applies: from the host's LACP perspective, the multihomed leaf pair must appear as a single logical LACP system. That generally requires a shared LACP system ID or coordinated system MAC behavior across the participating PEs. If each leaf presented a unique LACP system identity, the host would treat them as separate LAG partners and the all-active bundle would not form correctly. Reference: all-active L2 EVPN multi-homing, LAG attachment, LACP system ID behavior, Ethernet Segment association.
Which of the following statements about the decoupled gateway-based data center interconnect solution is TRUE?
Comprehensive and Detailed 150 to 250 words of Explanation From [SR Linux EVPN and Data Center Interconnect/Course Guide/topics]:
A decoupled gateway-based DCI model separates the data center border-leaf function from the WAN PE function. This separation is the key design point. The border leaf remains part of the data center EVPN/VXLAN environment, while the WAN PE participates in WAN VPN transport and policy enforcement. Because the roles are split across two devices, the handoff between the border leaf and WAN PE provides a clean administrative and operational boundary. That boundary is useful for security policy, QoS marking, traffic classification, and troubleshooting ownership. The WAN does not need direct reachability to every leaf and route reflector as in a gateway-less model. The WAN PE also does not peer directly with the data center route reflector in a decoupled model; route exchange occurs through the border-leaf/WAN-PE handoff. VXLAN tunnels between leaf routers across different data centers are characteristic of gateway-less extension, not decoupled gateway operation. Therefore, the statement about clear demarcation between the data center border leaf and WAN PE is the accurate description. Reference: decoupled gateway-based DCI, security/QoS demarcation, WAN PE separation.
Exam domains verified against: Official Nokia 4A0-D03 exam guide, last checked September 2026.
Understand the purpose and application of EVPN in data centers, including EVPN building blocks with MP-BGP control plane and VXLAN data plane. Study BGP EVPN route types, basic EVPN operations, and hands-on configuration of BGP and VXLAN tunnels for EVPN on SR Linux, including leaf and spine underlay networks and BGP route reflectors.
Sample question from this domain above: Q3
Learn L2 EVPN use cases and operations, including configuration of MAC-VRF for L2 EVPN with SR Linux CLI. Examine L2-related EVPN routes, MAC protection, MAC mobility and MAC duplication monitoring. Study proxy-ARP implementation for IP duplication detection and anti-spoofing in L2 EVPN environments.
Explain the use case for L3 EVPN; Describe the L3 EVPN Asymmetric Model and its implementation using the EVPN MAC/IP route type 2; Describe the L3 Symmetric Model and its implementation using the EVPN IP Prefix Route Type 5; Explain the purpose of IRB interfaces and the anycast-gateway IP address; Configure both an Asymmetric and Symmetric L3 EVPN with SR Linux CLI; Configure a L3 EVPN PE-CE BGP peering and verify how BGP path attributes are propagated across the EVPN; Hands-on Labs:; L3 EVPN – Asymmetric model with anycast-gateway IP addresses; L3 EVPN – Symmetric model with host-route advertising; Configure a PE-CE BGP peering in the L3 EVPN
Sample question from this domain above: Q2
Understand multi-homing use cases and redundancy modes including all-active and single-active configurations. Study Ethernet Segment concepts, designated forwarder election algorithms with EVPN route type 4, and the local-bias mechanism to prevent L2 traffic loops. Learn EVPN auto-discovery route type 1 variants for aliasing and mass withdrawals.
Sample question from this domain above: Q5
Learn data center interconnection options including gateway-less and gateway-based solutions over WAN networks. Configure and verify L2 EVPN DCI solutions demonstrating SR Linux interoperability with 7750 SR MPLS-based EVPN-VPLS and L3 EVPN DCI solutions with legacy MPLS-based IP-VPN solutions.
Sample question from this domain above: Q6
Common questions about the exam itself