300-410 Layer 3 Technologies Practice Question
A network engineer is implementing policy-based routing (PBR) on a Cisco IOS XE router. The router has two interfaces: GigabitEthernet0/0 (LAN) and GigabitEthernet0/1 (WAN). A route-map named PBR-MAP is applied to GigabitEthernet0/0 with the command `ip policy route-map PBR-MAP`. The route-map contains a match statement for access-list 101, which permits traffic from 10.1.1.0/24 to any destination. The set statement is `set ip next-hop 192.168.2.1`. However, traffic from 10.1.1.0/24 is still being routed according to the routing table instead of being forwarded to 192.168.2.1. Which action should the engineer take to ensure PBR is applied?
⚠ Common exam trap
The trap here is assuming that PBR can be enabled globally or applied outbound, when it must be applied inbound on the ingress interface.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Verify that the access-list 101 is correctly configured and matches the traffic, and that the route-map is applied to the correct interface in the inbound direction.
Policy-based routing requires the route-map to be applied to the inbound interface where traffic enters the router. The match conditions, such as an ACL, must correctly identify the traffic to be policy-routed. If the ACL is incorrect or the policy is not applied inbound, PBR will not override the routing table. Verifying these elements ensures that the policy is triggered and the set action is applied.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable PBR globally with the command `ip policy route-map PBR-MAP` in global configuration mode.
Why it's wrong here
PBR is not enabled globally; it is applied to an interface. The global command does not exist for enabling PBR. The route-map must be applied to the ingress interface where traffic arrives. In this scenario, the interface GigabitEthernet0/0 already has the policy applied, so this action would not resolve the issue.
- ✗
Configure a default route pointing to 192.168.2.1 to force all traffic through that next-hop.
Why it's wrong here
A default route would affect all traffic, not just the specified subset, and would not implement policy-based routing. PBR is used to override the routing table for specific traffic. Adding a default route does not guarantee that traffic from 10.1.1.0/24 will use 192.168.2.1, and it could disrupt other traffic.
- ✗
Apply the route-map to the outbound direction on GigabitEthernet0/1 instead of inbound on GigabitEthernet0/0.
Why it's wrong here
PBR is applied to inbound interfaces to influence the forwarding decision for traffic entering the router. Applying it outbound would not affect the routing decision for traffic arriving on GigabitEthernet0/0. Outbound route-maps are used for other purposes, such as filtering or marking, not for PBR.
- ✓
Verify that the access-list 101 is correctly configured and matches the traffic, and that the route-map is applied to the correct interface in the inbound direction.
Why this is correct
PBR requires that the route-map be applied to the inbound interface where traffic enters, and the match conditions (e.g., ACL) must correctly identify the traffic. If the ACL is misconfigured or the policy is applied in the wrong direction, PBR will not take effect. Checking these ensures the policy is properly triggered for the specified traffic.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every 300-410 question from scratch — 1,401 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.