300-410 Layer 3 Technologies Practice Question
A network engineer is configuring policy-based routing (PBR) on a Cisco IOS XE router. The router has two interfaces: GigabitEthernet0/0 (10.1.1.1/24) and GigabitEthernet0/1 (10.2.2.1/24). The engineer wants traffic from the 10.1.1.0/24 subnet destined to 192.168.1.0/24 to be forwarded out GigabitEthernet0/1 instead of following the routing table, which points to GigabitEthernet0/0. Which configuration sequence correctly implements this requirement?
⚠ Common exam trap
The trap here is assuming that an access list or static route can achieve source-based forwarding; PBR specifically requires a route map applied to an interface.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a route map that matches the source subnet and sets the next-hop to 10.2.2.2, then apply it to interface GigabitEthernet0/0 with the ip policy route-map command.
Policy-based routing allows the engineer to override the destination-based routing table by matching source addresses and setting a next-hop. The route map must be applied inbound on the interface where traffic enters the router. The set next-hop must point to a device reachable via the desired egress interface. This ensures only the specified source subnet is policy-routed, while other traffic follows normal routing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create a route map that matches the source subnet and sets the next-hop to 10.2.2.2, then apply it to interface GigabitEthernet0/0 with the ip policy route-map command.
Why this is correct
This is correct because PBR requires a route map to define match criteria (source subnet) and set actions (next-hop). Applying it inbound on the ingress interface GigabitEthernet0/0 ensures packets from 10.1.1.0/24 are policy-routed before the routing table is consulted. The next-hop 10.2.2.2 must be reachable via the interface the packet is forwarded out, which is GigabitEthernet0/1.
- ✗
Create an access list that permits the source subnet, apply it to interface GigabitEthernet0/1 with the ip access-group command, and set the default gateway to 10.2.2.2.
Why it's wrong here
This fails because an access list applied to an interface with ip access-group only filters or permits traffic; it does not alter the forwarding path. Changing the default gateway affects only the router's own traffic, not transit traffic. PBR requires a route map with set commands to override the routing table, not an ACL alone.
- ✗
Configure a static route for 192.168.1.0/24 pointing to 10.2.2.2 with a lower administrative distance, and redistribute it into the routing protocol.
Why it's wrong here
This would affect all traffic destined to 192.168.1.0/24, not just traffic from 10.1.1.0/24. The requirement is source-based policy routing, which static routes cannot achieve because they are destination-based. Redistribution is unnecessary and could cause routing loops or suboptimal paths for other sources.
- ✗
Enable PBR globally with the ip policy route-map command in global configuration mode, and reference a route map that sets the interface to GigabitEthernet0/1.
Why it's wrong here
PBR is not enabled globally; the ip policy route-map command is applied per interface in interface configuration mode. Additionally, the set clause uses next-hop or interface, but the route map must be applied on the ingress interface to intercept traffic. Global configuration does not exist for this purpose, so this approach is invalid.
Visual reference
Go deeper
Related to this question
About these practice questions
This 300-410 question is part of Courseiva's 1,401-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.