Courseiva
hardMultiple Choice

300-410 Practice Question: A network uses PBR to route traffic from a…

A network uses PBR to route traffic from a specific VLAN (10.10.10.0/24) through a firewall (next-hop 192.168.1.1). After a firewall replacement, traffic from this VLAN is being dropped. Router R1 shows: 'show route-map' shows the route-map is applied, 'show ip policy' shows the policy on the VLAN interface, but 'debug ip packet' shows packets being sent to 192.168.1.1 and no response. Router R2 (firewall) shows: 'show ip route 10.10.10.0' returns a route via 192.168.2.1, but the firewall is configured to drop traffic from 10.10.10.0/24. What is the root cause?

⚠ Common exam trap

300-410 often tests the tendency to blame the router configuration when the real issue is downstream — candidates overlook explicit firewall drop rules stated in the scenario.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The firewall is configured to drop traffic from the source subnet 10.10.10.0/24. Update the firewall policy to allow this traffic.

The firewall (R2) is explicitly configured to drop traffic from 10.10.10.0/24, as stated in the scenario. Even though PBR on R1 correctly forwards traffic to 192.168.1.1, the firewall drops it based on its policy. The root cause is the firewall's drop rule, which must be updated to allow the traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The firewall is configured to drop traffic from the source subnet 10.10.10.0/24. Update the firewall policy to allow this traffic.

    Why this is correct

    The route-map and policy are correctly forwarding packets to 192.168.1.1, but the replacement firewall explicitly drops traffic sourced from 10.10.10.0/24, so no response returns. Amending the firewall policy to permit that source subnet satisfies the connectivity constraint.

  • ✗

    The next-hop 192.168.1.1 is not reachable from R1 due to a routing issue.

    Why it's wrong here

    The debug output confirms R1 successfully forwards packets to 192.168.1.1, proving the next-hop is reachable from R1; the failure occurs at R2, which drops traffic from 10.10.10.0/24 per its configured policy. This option is tempting because a missing route to the next-hop is a common PBR failure cause, and it would be correct if R1’s ‘debug ip packet’ showed no ARP reply or ICMP unreachable for 192.168.1.1, indicating a Layer 3 reachability problem.

  • ✗

    The route-map on R1 is missing a 'set ip next-hop verify-availability' command, causing it to forward traffic to an unreachable next-hop.

    Why it's wrong here

    The firewall replacement changed the next-hop reachability, but R1 already forwards successfully to 192.168.1.1, so verify-availability would not alter the drop. That command tracks next-hop liveness via ICMP or object tracking, and would be correct where a PBR next-hop could silently fail without a routing-table entry.

  • ✗

    The VLAN interface on R1 has an ACL that is blocking traffic from 10.10.10.0/24.

    Why it's wrong here

    The debug output confirms packets reach 192.168.1.1, proving R1’s VLAN interface has no ACL blocking the source subnet; an ACL would drop packets before they leave R1, contradicting the debug evidence. This option is tempting because ACLs are commonly used to filter traffic from specific VLANs at the ingress interface, and in a scenario where packets never appear in debug output, an ACL would be the correct root cause.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

Courseiva writes every 300-410 question from scratch — 1,401 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.