Courseiva
Virtualization →mediumMultiple Choice

CCNP Virtualization Practice Question

A network engineer is configuring a Cisco CSR 1000v router to run multiple virtual routing and forwarding (VRF) instances. The engineer wants to ensure that traffic from VRF RED can reach the internet while traffic from VRF BLUE remains isolated. Which feature should be configured to allow VRF RED to access the global routing table?

⚠ Common exam trap

The trap here is thinking that simply configuring a routing protocol within each VRF will allow internet access, when in fact inter-VRF or VRF-to-global communication requires route leaking.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Route leaking using static routes with next-hop in the global table

Route leaking is the correct feature to allow traffic from a specific VRF to access the global routing table or another VRF. By configuring static routes or BGP import/export, the engineer can selectively leak routes for VRF RED to the global table, enabling internet access while maintaining isolation for VRF BLUE.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    MPLS L3VPN with route targets

    Why it's wrong here

    MPLS L3VPN uses route targets to control import and export of routes between VRFs, but it is typically used in service provider networks and requires MPLS enabled in the core. For a single router needing internet access from one VRF, MPLS L3VPN is overkill and not the simplest solution.

  • ✗

    GRE tunnel between VRF RED and the global table

    Why it's wrong here

    A GRE tunnel can be used to connect a VRF to the global table, but it adds complexity and overhead. Route leaking via static routes or BGP is the standard and simpler method to allow one VRF to access the global routing table while keeping other VRFs isolated.

  • ✗

    VRF-lite with OSPF process per VRF

    Why it's wrong here

    VRF-lite with OSPF per VRF provides routing within each VRF but does not automatically allow communication between VRFs or to the global table. Without route leaking, VRF RED would remain isolated from the internet, which is not the desired outcome.

  • ✓

    Route leaking using static routes with next-hop in the global table

    Why this is correct

    Route leaking allows selective import of routes between VRFs or between a VRF and the global table. By configuring a static route in VRF RED pointing to a global next-hop, or by using BGP import/export, you can allow VRF RED to reach the internet while keeping VRF BLUE isolated.

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.