Courseiva
Infrastructure Services →hardMultiple Choice

300-410 Infrastructure Services Practice Question

A network administrator is deploying MPLS Layer 3 VPNs with Cisco IOS XE routers. The administrator wants to ensure that customer routes are not leaked into the global routing table and that each VPN instance maintains separate routing and forwarding tables. Which of the following must be configured on the PE routers to achieve this isolation?

⚠ Common exam trap

The trap here is assuming that MPLS LDP or BGP route reflectors alone provide VPN isolation; they do not, VRFs are required.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

VRF definition with route distinguisher (RD) and route target (RT) import/export policies

To isolate customer routes in MPLS L3VPN, the PE router must have VRF instances. Each VRF has its own routing table, and the RD makes prefixes unique. RTs control which routes are imported into which VRF, enabling controlled route leaking. This architecture ensures that customer routes remain separate from the global table and from other customers. The other options are related to MPLS or BGP scaling but do not provide the required isolation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    BGP route reflectors with confederation

    Why it's wrong here

    BGP route reflectors and confederations are used to scale iBGP within an AS, reducing the full-mesh requirement. While they can be part of an MPLS VPN deployment, they do not provide the per-VPN routing table isolation. Route reflectors propagate routes, but without VRFs, the routes are still in the global BGP table. Therefore, this option does not achieve the required isolation of customer routes.

  • ✗

    OSPF sham links with domain ID

    Why it's wrong here

    OSPF sham links are used to connect OSPF areas through an MPLS VPN backbone, typically to avoid suboptimal routing or to connect two sites of the same OSPF domain across the VPN. Domain IDs help with area numbering. However, sham links do not create separate routing tables; they operate within a VRF. Without a VRF, there is no isolation. Thus, this option is not correct for achieving VPN instance separation.

  • ✗

    MPLS LDP with explicit-null and penultimate hop popping

    Why it's wrong here

    MPLS LDP distributes labels for the core network, and explicit-null or penultimate hop popping (PHP) affects label operations at the edge. However, these mechanisms do not provide VPN isolation. They are part of the transport label switching but do not create separate routing tables. Without VRFs, customer routes would still be in the global table. Thus, LDP configuration alone does not meet the requirement for VPN instance separation.

  • ✓

    VRF definition with route distinguisher (RD) and route target (RT) import/export policies

    Why this is correct

    A VRF (Virtual Routing and Forwarding) instance creates separate routing and forwarding tables per VPN. The route distinguisher (RD) makes the customer prefix unique within the MPLS domain, while route targets (RTs) control import and export of routes between VRFs. This combination ensures isolation and proper route leaking only where intended. Without VRFs, customer routes would mix with the global table or with other customers' routes, violating the isolation requirement.

Go deeper

Related to this question

About these practice questions

Courseiva writes every 300-410 question from scratch — 1,401 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.