Courseiva
Layer 3 Technologies →mediumMultiple Choice

300-410 Layer 3 Technologies Practice Question

A network engineer is configuring Policy-Based Routing (PBR) on a Cisco IOS-XE router. The engineer wants to route traffic from the 10.1.1.0/24 subnet that is destined for any TCP port 80 to next-hop 192.168.2.1, but only for packets arriving on GigabitEthernet0/1. Other traffic should follow the normal routing table. Which configuration sequence correctly accomplishes this?

⚠ Common exam trap

Candidates often confuse standard and extended ACLs for matching in route-maps, or applying PBR globally instead of on the ingress interface.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an extended ACL that permits tcp 10.1.1.0 0.0.0.255 any eq 80, reference it in a route-map match statement, set the next-hop to 192.168.2.1, and apply the route-map to interface GigabitEthernet0/1 with the ip policy route-map command.

The correct configuration uses an extended ACL to match both source subnet and destination TCP port 80, references it in a route-map, sets the next-hop, and applies the route-map inbound on the specified interface. This ensures only HTTP traffic from 10.1.1.0/24 arriving on GigabitEthernet0/1 is policy-routed, while other traffic follows normal routing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a route-map with a match statement for IP address 10.1.1.0/24 and a set statement for interface GigabitEthernet0/2, then apply it globally with the ip local policy route-map command.

    Why it's wrong here

    The ip local policy route-map command applies PBR to locally generated traffic from the router itself, not to transit traffic. Also, setting an interface rather than a next-hop may not achieve the desired forwarding if the interface is not directly connected to the destination. This does not policy-route transit traffic from the subnet.

  • ✗

    Create a standard ACL that permits 10.1.1.0 0.0.0.255, reference it in a route-map match statement, set the next-hop to 192.168.2.1, and apply the route-map to interface GigabitEthernet0/1 with the ip policy route-map command.

    Why it's wrong here

    A standard ACL can only match source IP addresses, not destination TCP port 80. This would policy-route all traffic from 10.1.1.0/24, not just HTTP traffic. The requirement specifically limits redirection to TCP port 80, so this configuration is too broad and incorrect.

  • ✗

    Create a route-map with a match statement for IP address 10.1.1.0/24 and a set statement for next-hop 192.168.2.1, then apply it to interface GigabitEthernet0/1 using the ip policy route-map command.

    Why it's wrong here

    This option matches only on source IP address, not on TCP port 80. It would policy-route all traffic from 10.1.1.0/24, not just HTTP traffic. The requirement specifies that only traffic destined for TCP port 80 should be redirected. Therefore, this configuration does not meet the scenario's conditional match.

  • ✓

    Create an extended ACL that permits tcp 10.1.1.0 0.0.0.255 any eq 80, reference it in a route-map match statement, set the next-hop to 192.168.2.1, and apply the route-map to interface GigabitEthernet0/1 with the ip policy route-map command.

    Why this is correct

    This correctly matches the source subnet and HTTP destination port using an extended ACL, then sets the next-hop for matching packets. Applying the route-map inbound on GigabitEthernet0/1 ensures only traffic arriving on that interface is policy-routed. This meets all conditions: specific source, specific destination port, and interface restriction.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

One of 1,401 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.