mediumMultiple Choice
300-410 Practice Question: Consider the following BGP configuration on…
Consider the following BGP configuration on router R2:
router bgp 65002
bgp router-id 2.2.2.2
neighbor 10.2.2.1 remote-as 65001 neighbor 10.2.2.1 route-map FILTER in
! route-map FILTER deny 10 match ip address prefix-list BLOCKED ! route-map FILTER permit 20 !
ip prefix-list BLOCKED permit 10.0.0.0/8 le 32
Which statement is true about routes received from 10.2.2.1?
⚠ Common exam trap
Many candidates confuse the effect of 'le' in prefix-lists: many candidates assume that '10.0.0.0/8 le 32' only matches the exact /8 prefix, but it actually matches all more specific prefixes as well. Another common mistake is misreading the route-map direction ('in' vs 'out').
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Routes with prefix 10.0.0.0/8 or more specific are denied; all others are permitted.
The prefix-list BLOCKED uses 'permit 10.0.0.0/8 le 32', which matches the 10.0.0.0/8 network and any more specific prefix (up to /32) within that range. The route-map FILTER denies any route matching this prefix-list in sequence 10, and permits all other routes in sequence 20. Since the route-map is applied inbound on neighbor 10.2.2.1, routes from that neighbor matching 10.0.0.0/8 or more specific are denied, while all other routes are accepted.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
All routes are accepted because the deny statement is misconfigured.
Why it's wrong here
The prefix-list permits 10.0.0.0/8 with le 32, matching any prefix within that range, so the deny statement actively drops those routes; the remaining routes are accepted by permit 20. Calling the deny misconfigured mistakes a deliberately broad match for an error.
- ✓
Routes with prefix 10.0.0.0/8 or more specific are denied; all others are permitted.
Why this is correct
The prefix-list matches 10.0.0.0/8 with le 32, covering the /8 itself and every more-specific subnet within it. Route-map sequence 10 denies those matches, while sequence 20 permits everything else, so only 10.0.0.0/8-derived prefixes are filtered.
- ✗
Only routes exactly matching 10.0.0.0/8 are denied; other 10.x.x.x routes are permitted.
Why it's wrong here
The prefix-list uses le 32, so 10.0.0.0/8 and every longer prefix within it, such as 10.1.0.0/16, match and are denied by sequence 10. Only routes outside 10.0.0.0/8 reach the permit 20 statement. Exact-match denial would require no le operator.
- ✗
The route-map is applied outbound, so it affects routes sent to 10.2.2.1.
Why it's wrong here
The neighbor statement carries the in keyword, so FILTER processes routes received from 10.2.2.1; outbound application would need the out keyword. Outbound route-maps are used to influence what a neighbour learns, typically for traffic engineering or filtering advertisements.
Go deeper
Related to this question
About these practice questions
One of 1,401 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.