Courseiva
Layer 3 Technologies →mediumMultiple Choice

300-410 Layer 3 Technologies Practice Question

A network engineer is implementing Policy-Based Routing (PBR) on a Cisco IOS router. The engineer wants to route traffic from subnet 10.10.10.0/24 to a next-hop of 192.168.2.2, but only for HTTP traffic (TCP port 80). Which configuration sequence is required?

⚠ Common exam trap

The trap here is forgetting that PBR matching for ports requires an extended ACL, and that the route-map must be applied to an interface, not globally.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an extended ACL that permits TCP port 80 from the subnet, create a route-map that matches the ACL and sets the next-hop, then apply the route-map to the interface with ip policy route-map.

PBR requires an extended ACL to match traffic based on source, destination, and port. The route-map then matches the ACL and sets the next-hop. Finally, the route-map is applied to the ingress interface with ip policy route-map. A standard ACL cannot match port numbers, and global application is not supported. Therefore, the sequence with an extended ACL and interface application is correct.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a route-map with a match statement for the source subnet and a set statement for the next-hop, then apply it globally with ip policy route-map.

    Why it's wrong here

    PBR route-maps are applied to interfaces, not globally. The ip policy route-map command is used under interface configuration. Applying it globally is not valid. Additionally, matching only the source subnet does not isolate HTTP traffic. This option is incorrect both in application method and in matching criteria. It would also not match port 80 without an extended ACL.

  • ✗

    Create a route-map with a match statement for the source subnet and a set statement for the next-hop, then apply it to the interface with ip policy route-map.

    Why it's wrong here

    This sequence is incomplete because it does not match HTTP traffic. PBR route-maps can match on extended ACLs that specify port numbers. Without matching TCP port 80, all traffic from the subnet would be policy-routed, not just HTTP. The engineer must include a match ip address statement referencing an extended ACL that permits TCP port 80. Thus, this option lacks the necessary granularity.

  • ✗

    Create a standard ACL that permits the subnet, create a route-map that matches the ACL and sets the next-hop, then apply the route-map to the interface with ip policy route-map.

    Why it's wrong here

    A standard ACL can only match source IP addresses, not port numbers. Therefore, it cannot distinguish HTTP traffic from other traffic. Using a standard ACL would result in all traffic from the subnet being policy-routed, which is not the requirement. The engineer must use an extended ACL to match TCP port 80. This option is incorrect because it lacks the ability to filter based on port.

  • ✓

    Create an extended ACL that permits TCP port 80 from the subnet, create a route-map that matches the ACL and sets the next-hop, then apply the route-map to the interface with ip policy route-map.

    Why this is correct

    This sequence correctly implements PBR for HTTP traffic. The extended ACL matches source subnet and destination TCP port 80. The route-map uses match ip address to reference the ACL and set ip next-hop to specify the next-hop. Applying the route-map to the ingress interface with ip policy route-map activates PBR. This ensures only HTTP traffic from the subnet is policy-routed, while other traffic follows normal routing.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

This 300-410 question is part of Courseiva's 1,401-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.