CCNP Virtualization Practice Question
A network engineer configured a Cisco IOS-XE router with VRF CUSTOMER_A and assigned Gi0/0/1 to it. The interface is up and has an IP address, but traffic sourced from the VRF cannot reach a remote prefix that is present in the global routing table. The engineer confirms the global route exists and the next hop is reachable. What is the most likely cause?
⚠ Common exam trap
The trap here is assuming that a route visible in the global routing table is automatically usable by traffic sourced inside a VRF.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The VRF has no route to the destination and requires route leaking or a default route
VRFs create fully isolated routing and forwarding tables on the same physical router. A prefix installed in the global table is not automatically available inside a VRF, and vice versa. To allow the VRF to reach that destination, the engineer must either redistribute or leak the route between the global table and the VRF, or install a default route inside the VRF.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The interface must be configured with the ip vrf forwarding command a second time
Why it's wrong here
The ip vrf forwarding command already moved the interface into CUSTOMER_A, which is confirmed by the interface being up with an address in the VRF. Re-entering the command would simply reassign the interface and remove its IP address, causing an outage rather than fixing reachability, so it cannot be the cause of the missing route.
- ✗
The global routing table entry is a recursive route that cannot be resolved
Why it's wrong here
The scenario states the next hop is reachable and the global route exists, so recursion is not the problem. Even a fully resolved global route remains invisible to the VRF because VRFs are isolated routing instances, meaning the failure is caused by table separation rather than by any resolution issue with the global entry.
- ✗
CEF is disabled on the router, forcing all traffic to be process-switched
Why it's wrong here
CEF being disabled would affect forwarding performance across the whole router but would not selectively prevent a VRF from reaching a global-table prefix. The described symptom is a routing table visibility issue, not a forwarding-path issue, so disabling CEF would not explain why the VRF lacks a route to the destination.
- ✓
The VRF has no route to the destination and requires route leaking or a default route
Why this is correct
A VRF maintains its own separate routing and forwarding table, so prefixes in the global table are not automatically visible inside CUSTOMER_A. Because the destination prefix exists only in the global table, the VRF has no matching route and drops the traffic. The engineer must either leak the global prefix into the VRF or provide a default route within the VRF.
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.