hardMultiple Choice
300-410 Practice Question: Runs the following command to troubleshoot a…
A network engineer runs the following command to troubleshoot a Policy-Based Routing (PBR) issue:
R1# debug ip policy
Policy routing debugging is on R1#
*Mar 1 00:15:30.789: IP: s=10.0.0.1 (FastEthernet0/0), d=20.0.0.1, len 100, policy match *Mar 1 00:15:30.789: IP: s=10.0.0.1 (FastEthernet0/0), d=20.0.0.1, len 100, policy rejected *Mar 1 00:15:30.789: IP: s=10.0.0.2 (FastEthernet0/0), d=20.0.0.2, len 100, policy match *Mar 1 00:15:30.789: IP: s=10.0.0.2 (FastEthernet0/0), d=20.0.0.2, len 100, policy routed *Mar 1 00:15:30.789: IP: FastEthernet0/0 to GigabitEthernet0/1 192.168.1.1
What does this output indicate?
⚠ Common exam trap
The trap here is assuming that 'policy match' always leads to successful routing; candidates may overlook that 'policy rejected' indicates a failure in the set action or a deny sequence, and they might incorrectly attribute the rejection to an ACL block rather than a route-map sequence issue.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The route-map has multiple sequences or ACL entries; one source is permitted, the other is denied or fails next-hop check.
The debug output shows two different source IPs (10.0.0.1 and 10.0.0.2) hitting the same PBR policy. For 10.0.0.1, the policy matches but is then rejected, meaning the route-map sequence matched but the set action (e.g., set ip next-hop) failed or the sequence was denied. For 10.0.0.2, the policy matches and is successfully routed to next-hop 192.168.1.1. This indicates the route-map has multiple sequences or ACL entries: one source is permitted and routed, the other is denied or fails a next-hop reachability check. The correct answer captures this multi-sequence behavior.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The route-map has multiple sequences or ACL entries; one source is permitted, the other is denied or fails next-hop check.
Why this is correct
The debug shows both a "policy match" then "policy rejected" for 10.0.0.1, versus "policy match" then "policy routed" for 10.0.0.2. This asymmetry confirms the route-map contains multiple sequences or ACL entries, so one source matches a permit statement with a valid next hop while the other hits a deny or fails the set next-hop check.
- ✗
Both packets should have been rejected due to a misconfiguration.
Why it's wrong here
The output shows one packet rejected and another policy routed, which is expected behaviour when the route map's match conditions differ per source; it is not a misconfiguration. This option would be right if both packets matched identical criteria yet produced inconsistent results.
- ✗
The next-hop 192.168.1.1 is unreachable for the first packet.
Why it's wrong here
The 'policy rejected' line means the route map matched but its set clause was not applied, so the packet fell through to normal destination-based routing; no next-hop reachability check is logged. This option would be right if the output showed the next-hop unresolved or a routing failure.
- ✗
The ACL is blocking all traffic from 10.0.0.1.
Why it's wrong here
'Policy rejected' indicates the route map matched but no set action applied, not that an ACL denied the traffic; a denied packet would show no policy match at all. This option would be correct if the debug output showed the packet failing an ACL check before policy evaluation.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every 300-410 question from scratch — 1,401 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.