hardMultiple ChoiceObjective-mapped
300-410 Practice Question: VRF route leaking between two VRFs is causing…
VRF route leaking between two VRFs is causing unexpected reachability to a sensitive subnet. Router R1 has the following relevant configuration: vrf definition BLUE rd 100:1 ! address-family ipv4 route-target export 100:1 route-target import 100:2 vrf definition RED rd 100:2 ! address-family ipv4 route-target export 100:2 route-target import 100:1 interface GigabitEthernet0/0 vrf forwarding BLUE ip address 10.1.1.1 255.255.255.0 interface GigabitEthernet0/1 vrf forwarding RED ip address 10.2.2.1 255.255.255.0 router ospf 1 vrf BLUE network 10.1.1.0 0.0.0.255 area 0 router ospf 2 vrf RED network 10.2.2.0 0.0.0.255 area 0 A ping from a host in BLUE VRF to 10.2.2.2 (RED VRF) succeeds, but it should not. What is the root cause?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Route-target import/export is symmetric, causing full route exchange; use route-map to filter.
The route-target import/export configuration is bidirectional, causing full route leaking between VRFs. This allows hosts in BLUE to reach RED subnets. The correct fix is to use import/export only for specific prefixes or use route-maps to control leaking.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Route-target import/export is symmetric, causing full route exchange; use route-map to filter.
Why this is correct
Both VRFs import each other's routes, so all routes are leaked. Route-maps can restrict which prefixes are imported.
- ✗
The OSPF process IDs are different; they should be the same for route leaking.
Why it's wrong here
OSPF process IDs are local; route leaking is via VRF, not OSPF.
- ✗
The network commands are missing the vrf keyword; add vrf BLUE/RED.
Why it's wrong here
The network commands are under the VRF OSPF process, so correct.
- ✗
The interfaces are in the wrong VRF; move GigabitEthernet0/1 to BLUE.
Why it's wrong here
Interfaces are correctly assigned; the issue is route leaking.
Visual reference
Quick reference
Routing Protocol Comparison
| Protocol | Metric | Max Hops | Algorithm | Type |
|---|---|---|---|---|
| RIP v2 | Hop count | 15 | Bellman-Ford | Distance vector |
| OSPF | Cost (bandwidth) | Unlimited | Dijkstra (SPF) | Link state |
| EIGRP | Composite metric | Unlimited | DUAL | Hybrid |
| IS-IS | Cost | Unlimited | Dijkstra | Link state |
| BGP | Policy / attributes | Unlimited | Path vector | Path vector |
RIP's 15-hop limit makes it unsuitable for large networks. OSPF and EIGRP dominate modern enterprise deployments.
Go deeper
Related to this question
Learn chapter
Introduction to ENARSI Exam and Network Fundamentals
Key term
MPLS Layer 3 VPN
A technology that uses Multiprotocol Label Switching to create secure, scalable virtual private networks that connect multiple sites at the network layer, where the service provider manages routing between customer sites.
About these practice questions
One of 1,966 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.