350-501 Security and Services Practice Question
An SP is deploying BGP security features. Which three mechanisms can be used to prevent BGP route hijacking? (Choose three.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Prefix-lists to filter customer routes
RPKI validates origin AS, prefix-list filters prefixes, and route-maps can apply additional filters. BGP communities are used for tagging, not direct hijacking prevention. AS-path prepending is for path selection, not hijacking.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Prefix-lists to filter customer routes
Why this is correct
Prefix-lists restrict which prefixes are accepted.
- ✓
RPKI with BGP Origin Validation
Why this is correct
RPKI validates that the origin AS is authorized.
- ✗
AS-path prepending
Why it's wrong here
AS-path prepending influences path selection, not hijacking prevention.
- ✓
Route-maps to match and set attributes
Why this is correct
Route-maps can filter and modify routes to prevent hijacking.
- ✗
BGP communities to tag routes
Why it's wrong here
Communities are for policy propagation, not direct hijacking prevention.
Go deeper
Related to this question
About these practice questions
This 350-501 question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-501 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-501 exam.