mediumMultiple Select
CCNP Practice Question: Which three statements about VRF path isolation…
Which three statements about VRF path isolation in a service provider network are true? (Choose three.)
⚠ Common exam trap
The trap is confusing VRF with VLANs for Layer 2 isolation, or thinking VRF-lite uses MPLS labels. Candidates might also overlook that VRF-aware features can be applied per VRF.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
VRFs allow multiple customers to share the same physical infrastructure while keeping their traffic isolated.
Option A is correct because a VRF (Virtual Routing and Forwarding) instance creates a separate routing table on the same physical router, so multiple customers can share the provider's physical infrastructure while their traffic and routing information remain logically isolated. Option B is correct because in MPLS L3VPN, each VRF is associated with route targets (extended BGP communities) that control which routes are exported from and imported into the VRF, thereby governing route distribution between PE routers. Option C is correct because VRF-aware features such as NAT, QoS, and ACLs can be configured within a specific VRF context, allowing per-VRF policy enforcement that maintains path isolation between customers. Option D is not correct because VRFs operate at Layer 3 by separating routing tables, whereas VLANs provide Layer 2 broadcast-domain isolation; VRF does not replace VLANs for Layer 2 segmentation. Option E is not correct because VRF-lite achieves isolation using separate routing/forwarding tables and interfaces (typically without MPLS), not by using MPLS labels.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
VRFs allow multiple customers to share the same physical infrastructure while keeping their traffic isolated.
Why this is correct
VRFs provide logical separation at Layer 3 by maintaining independent routing and forwarding tables per customer on shared hardware. This satisfies the stem's path isolation requirement, letting overlapping address space coexist without leakage between tenants across the same physical service provider infrastructure.
- ✓
In MPLS VPN, VRFs are combined with route targets to control route distribution between PE routers.
Why this is correct
In MPLS VPN, route targets are extended BGP community attributes attached to VPNv4 routes, determining which VRFs import or export them. This controls route distribution between PE routers, satisfying the stem's requirement for combining VRFs with route targets.
- ✓
VRF-aware features such as NAT, QoS, and ACLs can be applied per VRF to enforce path isolation policies.
Why this is correct
VRF-aware NAT, QoS and ACLs operate within each routing table's forwarding context, so policy is enforced per tenant rather than globally. This satisfies the stem's path isolation requirement by keeping traffic separated end to end, letting each VRF carry independent filtering, marking and translation rules without leaking between customers.
- ✗
VRF can be used to replace VLANs for Layer 2 isolation.
Why it's wrong here
VRF provides Layer 3 routing table separation, not Layer 2 broadcast-domain isolation, so it cannot replace VLANs. It is tempting because VRFs and VLANs are both isolation mechanisms and are often mapped together, but VLANs segment Ethernet frames while VRFs segment IP routing instances.
- ✗
In VRF-lite, path isolation is achieved using MPLS labels.
Why it's wrong here
VRF-lite achieves path isolation through separate routing and forwarding tables on the same device, without MPLS labels; label-based isolation belongs to full MPLS L3VPN. It is tempting because both approaches separate customer traffic, but VRF-lite is specifically the label-free variant.
Visual reference
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.