300-410 Layer 3 Technologies Practice Question
A network engineer is troubleshooting a Cisco IOS XE router that is configured with a route map for policy-based routing (PBR). The route map is applied to the ingress interface with `ip policy route-map PBR`. The engineer wants to verify that the PBR is matching traffic and setting the next-hop correctly. Which command provides the most detailed information about PBR matches and actions?
⚠ Common exam trap
The trap here is assuming that `show route-map` displays full PBR match and action details, when it only shows configuration and basic counters.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
debug ip policy
For detailed PBR troubleshooting, `debug ip policy` is the most informative command. It logs each packet's match against route map sequences and shows the set actions applied, such as next-hop or interface. While `show route-map` provides configuration and some counters, it lacks the per-packet detail. `show ip policy` only confirms attachment. Thus, the debug command is the correct choice for verifying matches and next-hop settings.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
show route-map PBR
Why it's wrong here
The `show route-map PBR` command displays the configuration of the route map, including match and set clauses, and may show packet counts for each sequence if the route map is used for PBR. However, it does not show the actual next-hop being set or detailed match information for specific flows. It provides limited statistics, such as match counts, but not the granular detail needed to verify next-hop selection.
- ✓
debug ip policy
Why this is correct
The `debug ip policy` command provides real-time detailed output about PBR processing, including which route map sequence is matched, the packet's source and destination, and the resulting action such as setting the next-hop or interface. It is the most detailed troubleshooting tool for PBR, showing exactly how packets are handled. However, it can be CPU-intensive and should be used with caution in production.
- ✗
show ip policy
Why it's wrong here
The `show ip policy` command lists the route maps applied to interfaces for PBR, along with the interface names. It confirms which policy is attached where, but it does not provide any details about whether the policy is matching traffic or what actions are being taken. It is useful for verifying configuration, but not for troubleshooting match statistics or next-hop settings.
- ✗
show ip route
Why it's wrong here
The `show ip route` command displays the routing table, which includes routes installed by the routing protocol or static configuration. PBR does not install routes into the routing table; it overrides the routing table for specific traffic. Therefore, this command will not show PBR matches or actions. It might show the default route or other routes, but not the policy-based decisions.
Go deeper
Related to this question
About these practice questions
This 300-410 question is part of Courseiva's 1,401-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.