hardMultiple Choice
300-410 Practice Question: An engineer configures a route-map to filter OSPF…
An engineer configures a route-map to filter OSPF routes using a distribute-list. The distribute-list is applied inbound on an OSPF interface. Unexpectedly, the router still installs the filtered routes. Which is the most likely explanation?
⚠ Common exam trap
Cisco often tests the misconception that a distribute-list applied inbound on one interface will globally prevent a route from being installed, when in fact it only filters routes from that specific neighbor, and the route may still be installed from another neighbor.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The route is also learned via another OSPF neighbor that is not filtered by the distribute-list.
When a distribute-list is applied inbound on an OSPF interface, it filters routes received from that specific neighbor only. If the same route is also learned from another OSPF neighbor (or via a different OSPF process) that is not covered by the distribute-list, the router will still install that route from the unfiltered source. This is because OSPF installs the best route based on metric, regardless of the filtering applied to a single neighbor.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The distribute-list is applied to the wrong direction; it should be outbound to filter routes being advertised.
Why it's wrong here
The distribute-list direction is not the problem; inbound filtering on the interface is the correct way to prevent a route from being installed. Outbound distribute-lists only affect routes advertised to other OSPF neighbors and have no impact on local routing table installation. The real issue is that OSPF may receive the same prefix from another neighbor not covered by this inbound filter.
- ✓
The route is also learned via another OSPF neighbor that is not filtered by the distribute-list.
Why this is correct
OSPF can learn the same prefix from multiple neighbors, and each received route is independently evaluated against any distribute-list applied to that specific incoming interface. If the route is also learned via another OSPF neighbor on a different interface that has no distribute-list, that copy is installed in the routing table without restriction. This is exactly why the route appears despite the filter: the distribute-list only blocks reception on one interface, not the entire OSPF process.
- ✗
The distribute-list uses an ACL that does not match the route exactly, so the route is permitted.
Why it's wrong here
A distribute-list relies on an ACL to match route prefixes, and an ACL that does not contain the exact network statement will fall through to the implicit permit at the end, allowing the route. However, this is not the cause in this scenario because even a perfectly matched ACL would still fail to block the route if it is also learned from another OSPF neighbor. The engineer's filter cannot work when a parallel path exists in OSPF, so the ACL mismatch is irrelevant to the observed behavior.
- ✗
The distribute-list is applied after the route is already installed in the routing table, so it has no effect.
Why it's wrong here
Distribute-lists are applied to routing updates during the route installation process, before the route is inserted into the RIB; they do not remove routes that are already present. If a route is already installed, applying a distribute-list later will not flush it from the table. In this case, the route is still being learned from an unfiltered neighbor, so the fact that distribute-lists work pre-installation is not the reason the route remains.
Visual reference
Quick reference
Routing Protocol Comparison
| Protocol | Metric | Max Hops | Algorithm | Type |
|---|---|---|---|---|
| RIP v2 | Hop count | 15 | Bellman-Ford | Distance vector |
| OSPF | Cost (bandwidth) | Unlimited | Dijkstra (SPF) | Link state |
| EIGRP | Composite metric | Unlimited | DUAL | Hybrid |
| IS-IS | Cost | Unlimited | Dijkstra | Link state |
| BGP | Policy / attributes | Unlimited | Path vector | Path vector |
RIP's 15-hop limit makes it unsuitable for large networks. OSPF and EIGRP dominate modern enterprise deployments.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 300-410 question from scratch — 1,401 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.