CCNP Virtualization Practice Question
A network engineer is configuring a Cisco Catalyst 9000 switch to support a virtual routing and forwarding (VRF) instance for a guest network. The engineer wants to ensure that traffic from the guest VRF cannot leak into the corporate VRF. Which configuration step is required to maintain isolation between VRFs?
⚠ Common exam trap
The trap here is overcomplicating VRF isolation by thinking that route targets or inter-VLAN routing are needed, when simply placing interfaces in the VRF without route leaking is sufficient.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Place the guest network interfaces into the guest VRF and do not configure any route leaking.
VRFs provide logical separation of routing tables. When you assign interfaces to a VRF, those interfaces use that VRF's routing table. By default, there is no communication between VRFs unless you explicitly configure route leaking, such as static routes with next-hop VRF or BGP route targets. Therefore, placing the guest interfaces in the guest VRF and not configuring any route leaking ensures isolation. Other options either do not enforce isolation or are unnecessary.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Assign the guest VRF to a separate VLAN and configure inter-VLAN routing.
Why it's wrong here
Assigning a separate VLAN and enabling inter-VLAN routing would actually allow communication between the VRFs if the switch routes between them. Inter-VLAN routing connects subnets, which could defeat isolation. To maintain isolation, you must not enable routing between the VRFs unless explicitly desired. This step does not enforce isolation.
- ✗
Configure a route target export and import policy to control route leaking.
Why it's wrong here
Route targets are used in MPLS L3VPN and EVPN to control route distribution between VRFs. On a standalone Catalyst 9000, VRFs are isolated by default, and route leaking is not controlled by route targets. While route targets can be used in VRF-lite with BGP, they are not the primary isolation mechanism on a single switch. This is not the required step for basic isolation.
- ✓
Place the guest network interfaces into the guest VRF and do not configure any route leaking.
Why this is correct
VRF instances are isolated by default. By assigning interfaces to the guest VRF, traffic within that VRF is separate from the corporate VRF. As long as no route leaking (such as static routes or BGP route targets) is configured, the VRFs remain isolated. This is the correct and sufficient step to maintain isolation.
- ✗
Enable VRF-aware routing and ensure no static routes point between VRFs.
Why it's wrong here
VRF-aware routing is automatic once interfaces are assigned to VRFs. The key is to avoid configuring routes that cross VRFs. However, the question asks for the required step to maintain isolation. The most fundamental step is to place interfaces into the correct VRF. This option is partially correct but not the specific configuration step that enforces isolation.
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.