300-410 Layer 3 Technologies Practice Question
A network engineer is configuring policy-based routing (PBR) on a Cisco IOS XE router. The router has two interfaces: GigabitEthernet0/0 (LAN) and GigabitEthernet0/1 (WAN). The engineer wants all HTTP traffic from the 10.1.1.0/24 subnet to be routed via next-hop 192.168.2.2 instead of the default route. The engineer creates a route map named PBR with sequence 10, matches an ACL that permits TCP port 80 from 10.1.1.0/24, and sets the next-hop to 192.168.2.2. The route map is applied to interface GigabitEthernet0/0 with the command `ip policy route-map PBR`. However, traffic still follows the default route. Which action will fix the problem?
⚠ Common exam trap
The trap here is assuming that PBR automatically works once the route map is created and applied, without verifying that the ACL matches the traffic correctly.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Ensure the ACL used in the route map matches the correct source and destination addresses and ports, and that the route map is applied in the correct direction.
Policy-based routing (PBR) on Cisco IOS XE requires that the route map is applied to the interface where traffic enters the router and that the ACL matches the intended traffic. Common oversights include misconfigured ACLs (wrong source, destination, or port) or applying the policy to the wrong interface. Ensuring the ACL matches HTTP traffic from 10.1.1.0/24 and that the route map is applied inbound on GigabitEthernet0/0 will make PBR function as intended.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Ensure the ACL used in the route map matches the correct source and destination addresses and ports, and that the route map is applied in the correct direction.
Why this is correct
Policy-based routing requires that the ACL correctly identifies the traffic to be policy-routed. The ACL must permit TCP port 80 from 10.1.1.0/24 to any destination. Additionally, the route map must be applied to the ingress interface (GigabitEthernet0/0) in the inbound direction, which is the default when using the `ip policy route-map` command. Verifying these elements will resolve the issue.
- ✗
Configure the `ip local policy route-map PBR` command to apply the route map globally.
Why it's wrong here
The `ip local policy route-map` command applies policy-based routing to locally generated traffic from the router itself, not to transit traffic from the LAN. This would not affect traffic from the 10.1.1.0/24 subnet. The issue is that the route map is not matching the traffic correctly.
- ✗
Apply the route map to the GigabitEthernet0/1 interface instead of GigabitEthernet0/0.
Why it's wrong here
Applying the route map to GigabitEthernet0/1 would affect traffic entering from the WAN, not the LAN traffic from 10.1.1.0/24. Policy-based routing must be applied to the interface where the traffic enters the router. Since the LAN traffic enters on GigabitEthernet0/0, the policy is correctly applied there.
- ✗
Add the `set ip next-hop verify-availability` command to the route map.
Why it's wrong here
The `set ip next-hop verify-availability` command is used to verify the reachability of the next-hop before using it. It does not affect whether the route map is applied or whether the policy is evaluated. The issue here is that the policy is not being applied to the correct traffic direction, not next-hop reachability.
Visual reference
Go deeper
Related to this question
About these practice questions
This 300-410 question is part of Courseiva's 1,401-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.