Courseiva
hardMultiple Select

300-410 Practice Question: Which TWO statements about MPLS label stack…

Which TWO statements about MPLS label stack operations in a Layer 3 VPN (L3VPN) are true? (Choose TWO.)

⚠ Common exam trap

The trap is confusing the roles of the P router and the egress PE, and thinking that P routers process the inner VPN label or that the egress PE swaps labels instead of popping.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A P router (core router) performs label swapping only on the top label in the label stack.

Option A is correct because a P (provider core) router in an MPLS L3VPN only processes the top label of the stack for its label-switching (LFIB) lookup, performing a swap operation on that outer label without examining the inner VPN label. Option B is correct because the ingress PE router imposes a two-label stack: the outer label is distributed by LDP (or RSVP-TE) for transport across the provider core, and the inner label is the VPN label (typically MP-BGP/VRF label) that identifies the destination VRF at the egress PE. Option C is incorrect because the penultimate P router (PHP) or the egress PE pops the outer transport label, not the inner VPN label; the VPN label is removed only at the egress PE after VRF lookup. Option D is incorrect because the egress PE removes the VPN label and performs an IP lookup in the VRF table before forwarding the packet to the CE; it does not swap the VPN label for a new label. Option E is incorrect because P routers forward based solely on the top (outer) label and never inspect the inner VPN label, which is only meaningful to the egress PE.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    A P router (core router) performs label swapping only on the top label in the label stack.

    Why this is correct

    P routers forward solely on the top label, swapping it per the LFIB and leaving inner labels untouched. The inner VPN label is only examined by the egress PE, so core forwarding stays label-stack agnostic.

  • ✓

    The ingress PE router imposes two labels: an outer LDP label and an inner VPN label.

    Why this is correct

    The ingress PE pushes an outer LDP label, used by core P routers to forward traffic hop-by-hop, and an inner VPN label, used by the egress PE to identify the correct VRF. This two-label stack satisfies the L3VPN requirement for separating core transport forwarding from customer route differentiation.

  • ✗

    The P router pops the inner VPN label before forwarding the packet to the egress PE.

    Why it's wrong here

    Penultimate hop popping removes the outer transport label at the penultimate router; the inner VPN label survives until the egress PE, which is the only device that processes it. Confusing the two labels is tempting because PHP does pop a label, but never the VPN one.

  • ✗

    The egress PE router swaps the VPN label with a new label before forwarding to the CE.

    Why it's wrong here

    The egress PE removes the VPN label and forwards a plain IP packet to the CE; label swapping happens at transit routers on the transport label. It is tempting because swapping is a genuine MPLS operation, but it applies to the outer label, not the VPN label at egress.

  • ✗

    The P router uses the inner VPN label to make forwarding decisions.

    Why it's wrong here

    The P router forwards on the outer transport label only; the inner VPN label is examined by the egress PE, which maps it to the correct VRF. It is tempting because the VPN label does identify the customer, but core routers never read it — that is the whole point of label stacking.

Go deeper

Related to this question

About these practice questions

This 300-410 question is part of Courseiva's 1,401-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.