350-501 Services Practice Question
A service provider recently deployed MPLS L3VPN for a customer with four sites (Site1, Site2, Site3, Site4) connected to PE1, PE2, PE3, and PE4 respectively. All sites are in VRF CUST-A with route targets 100:1 import and 100:1 export on all PEs. The customer reports that Site4 cannot ping the loopback interface (10.1.1.1/32) of Site1, but Site2 and Site3 can reach it. The provider verifies that BGP sessions between all PEs and the route reflector are up and that VPNv4 routes are advertised. The VRF on PE4 shows the route 10.1.1.1/32 with next-hop 192.0.2.1 (PE1's loopback) but when Site4 initiates a ping, it fails. What should the provider check next?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Check the VRF route target import on PE1 to ensure it includes the route target exported by PE4 for Site4's subnet.
The issue is that return traffic from Site1 to Site4 is being dropped. Although PE4 has the route to Site1's loopback, PE1 needs to have a route back to Site4's subnet in its VRF CUST-A. This is achieved by ensuring that PE1 imports the correct route target (exported by PE4 for Site4's prefix). If the import RT on PE1 does not include the RT that PE4 exports for Site4, the return path is broken. Option A is incorrect because the IGP propagation of loopback interfaces is not directly related to VPNv4 route reachability; BGP sessions are already up. Option B is incorrect because the BGP session between PE4 and the route reflector is already up, and update source issues would affect route advertisement, not return path. Option C is incorrect because CE configuration is likely fine since Site2 and Site3 work.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Ensure that the IGP operating in the core has propagated the loopback interface address of PE1 to all P routers.
Why it's wrong here
Incorrect. The IGP propagation of loopback interfaces is not directly related to VPNv4 route reachability; BGP sessions are already up, and the route is learned in the VRF.
- ✗
Verify that the BGP session between PE4 and the route reflector is using the correct update source.
Why it's wrong here
Incorrect. The BGP session between PE4 and the route reflector is already up, and update source issues would affect route advertisement, not return path routing.
- ✗
Verify that the CE router at Site4 is configured with the correct VRF name and default gateway.
Why it's wrong here
Incorrect. CE configuration is likely fine since Site2 and Site3 work, indicating that the CE at Site4 is probably configured correctly.
- ✓
Check the VRF route target import on PE1 to ensure it includes the route target exported by PE4 for Site4's subnet.
Why this is correct
Correct. The ping fails because return traffic from Site1 to Site4 is dropped. PE1 must import the route target exported by PE4 for Site4's subnet. If the import RT on PE1 does not include the RT from PE4, the return path is broken.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every 350-501 question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-501 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-501 exam.