Courseiva
Layer 3 Technologies →mediumMultiple Choice

300-410 Layer 3 Technologies Practice Question

A network engineer is configuring Policy-Based Routing (PBR) on a Cisco router. The goal is to forward all HTTP traffic (TCP port 80) from the 10.1.1.0/24 subnet to next-hop 192.168.2.1. Which configuration sequence is correct?

⚠ Common exam trap

The trap here is using a standard ACL or trying to match ports directly in a route-map; PBR requires an extended ACL to match port numbers, and it is applied inbound on the interface.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an extended ACL that permits TCP port 80 from 10.1.1.0/24 to any, reference it in a route-map with a match ip address statement, set the next-hop to 192.168.2.1, and apply the route-map to the incoming interface with the ip policy route-map command.

PBR requires an ACL to classify traffic based on source, destination, and port. An extended ACL can match TCP port 80. The route-map then matches the ACL and sets the next-hop. Finally, the route-map is applied to the incoming interface with the ip policy route-map command. The other options either match all traffic, use a standard ACL that cannot match ports, or attempt to match ports directly in a route-map, which is not supported.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a route-map with a match statement for TCP port 80 and a set statement for next-hop 192.168.2.1, then apply it globally with the ip policy route-map command.

    Why it's wrong here

    Route-maps do not support matching TCP port numbers directly; they require an ACL to match ports. Also, the ip policy route-map command is applied to an interface, not globally. There is no global command to apply PBR. This configuration is invalid and would not achieve the desired routing.

  • ✗

    Create a standard ACL that permits 10.1.1.0/24, reference it in a route-map with a match ip address statement, set the next-hop to 192.168.2.1, and apply the route-map to the outgoing interface with the ip policy route-map command.

    Why it's wrong here

    A standard ACL can only match source IP addresses, not port numbers. Therefore, it cannot distinguish HTTP traffic from other traffic. Additionally, PBR is applied to the incoming interface, not outgoing. This configuration would route all traffic from the subnet and would not work as intended.

  • ✗

    Create a route-map with a match statement for IP address 10.1.1.0/24 and a set statement for next-hop 192.168.2.1, then apply it to the incoming interface with the ip policy route-map command.

    Why it's wrong here

    This configuration matches all traffic from the subnet, not just HTTP traffic. The requirement is to forward only HTTP traffic (TCP port 80). The match statement should also include a match for the port. Therefore, this is incomplete and would route all traffic, not just HTTP.

  • ✓

    Create an extended ACL that permits TCP port 80 from 10.1.1.0/24 to any, reference it in a route-map with a match ip address statement, set the next-hop to 192.168.2.1, and apply the route-map to the incoming interface with the ip policy route-map command.

    Why this is correct

    This sequence correctly identifies HTTP traffic using an extended ACL, matches it in a route-map, sets the next-hop, and applies the route-map to the incoming interface. PBR uses route-maps with match statements based on ACLs to classify traffic, and the ip policy route-map command enables PBR on the interface. This meets the requirement precisely.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

This 300-410 question is part of Courseiva's 1,401-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.