Courseiva
Layer 3 Technologies →mediumMultiple Choice

300-410 Layer 3 Technologies Practice Question

A network engineer is configuring policy-based routing (PBR) on a Cisco IOS XE router. The engineer wants traffic from subnet 10.1.1.0/24 to be forwarded to next-hop 192.168.2.1, while all other traffic uses the default routing table. The engineer configures a route map and applies it to the ingress interface with `ip policy route-map PBR`. However, traffic from 10.1.1.0/24 is still following the default route. Which action should the engineer take to ensure PBR is applied?

⚠ Common exam trap

The trap here is assuming that simply applying a route map is sufficient, without verifying the match/set statements and the correct ingress interface application.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Verify that the route map contains a match statement for the source subnet and a set statement for the next-hop, and that the route map is applied with the `ip policy route-map` command on the correct interface.

PBR requires a route map with proper match and set statements, and it must be applied to the ingress interface where the traffic enters. If the route map lacks a match for the source subnet or a set for the next-hop, or if it is applied incorrectly, PBR will not override the default routing. Verifying these elements ensures that traffic from 10.1.1.0/24 is forwarded to 192.168.2.1 as intended.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Verify that the route map contains a match statement for the source subnet and a set statement for the next-hop, and that the route map is applied with the `ip policy route-map` command on the correct interface.

    Why this is correct

    PBR requires a route map with at least one match statement (e.g., `match ip address` referencing an ACL for 10.1.1.0/24) and a set statement (e.g., `set ip next-hop 192.168.2.1`). The route map must be applied to the ingress interface with `ip policy route-map PBR`. If the match or set is missing, or if applied to the wrong interface, PBR will not take effect. This option correctly identifies the necessary configuration elements.

  • ✗

    Enable `ip local policy route-map PBR` globally to apply the policy to all interfaces.

    Why it's wrong here

    `ip local policy route-map` applies PBR to locally generated traffic from the router itself, not to transit traffic. The scenario describes traffic from a subnet, which is transit traffic that arrives on an interface. Applying a local policy would not affect that traffic. The correct application is on the ingress interface using `ip policy route-map`. Therefore, this command does not solve the problem.

  • ✗

    Apply the route map to the egress interface with the `ip policy route-map` command.

    Why it's wrong here

    PBR is applied to ingress traffic on the interface where packets arrive, not on the egress interface. Applying it to the egress interface would not affect the forwarding decision, as the routing decision is made before the packet is forwarded out. The correct placement is on the ingress interface. Therefore, this action would not cause PBR to take effect for the specified subnet.

  • ✗

    Configure a default route with a next-hop of 192.168.2.1 to override the existing default route.

    Why it's wrong here

    Adding a default route would affect all traffic, not just the subnet 10.1.1.0/24. PBR is designed to selectively override routing for specific traffic. Changing the default route would disrupt other traffic and does not implement the desired policy. The issue is that PBR is not correctly configured or applied, not that the default route is missing. This action would not selectively forward the subnet's traffic.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

One of 1,401 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.