Courseiva
Layer 3 Technologies →hardMultiple Choice

300-410 Layer 3 Technologies Practice Question

A network administrator is configuring MPLS Layer 3 VPN on a Cisco IOS XE router. The router is a PE device connected to two CE routers in different VRFs. The administrator wants to prevent routes from one VRF from being leaked into another VRF. Which configuration step is essential to maintain VRF separation?

⚠ Common exam trap

A common mix-up: candidates confuse the role of the route distinguisher with that of the route target; the RD only makes prefixes unique, while RTs control import/export into VRFs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure route targets (RTs) for import and export on each VRF.

In MPLS Layer 3 VPN, VRF separation is achieved through the use of route targets (RTs). Each VRF is configured with import and export RTs. When a route is exported from a VRF, it is tagged with the export RT. The receiving PE imports the route into a VRF only if the route's RT matches the VRF's import RT. Therefore, to prevent leaking, each VRF must have unique RTs that are not shared with other VRFs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Configure route targets (RTs) for import and export on each VRF.

    Why this is correct

    Route targets control which routes are imported into and exported from a VRF. By assigning distinct RTs for import and export on each VRF, you ensure that routes from one VRF are not imported into another. This maintains VRF separation. Without proper RT configuration, routes could be leaked between VRFs if RTs are shared.

  • ✗

    Enable OSPF as the PE-CE routing protocol and use different process IDs.

    Why it's wrong here

    Using different OSPF process IDs on the PE for each VRF is a common practice, but it does not inherently prevent route leaking. Route leaking is controlled at the BGP VPNv4 level via route targets. Even with separate OSPF processes, if RTs are misconfigured, routes can still be imported into the wrong VRF.

  • ✗

    Assign a unique route distinguisher (RD) to each VRF.

    Why it's wrong here

    A unique RD is used to make VPNv4 prefixes unique across the MPLS domain, but it does not by itself prevent route leaking between VRFs. Route leaking is controlled by route targets (RTs). The RD is appended to the IPv4 prefix to create a VPNv4 prefix, but import/export of routes into VRFs is governed by RTs.

  • ✗

    Configure BGP neighbor statements with different autonomous system numbers.

    Why it's wrong here

    Using different AS numbers for BGP neighbors does not prevent route leaking between VRFs. The separation is enforced by route targets in the VPNv4 address family. BGP AS numbers are used for loop prevention and path selection, not for VRF isolation. Misconfigured RTs would still cause leaking regardless of AS numbers.

Go deeper

Related to this question

About these practice questions

Courseiva writes every 300-410 question from scratch — 1,401 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.