Courseiva
hardMultiple Choice

300-410 Practice Question: An engineer configures PBR with a route-map that…

An engineer configures PBR with a route-map that sets the next-hop to 10.0.0.2 for traffic matching ACL 100. The route-map is applied inbound on interface GigabitEthernet0/1. Traffic from a host on that interface is forwarded via 10.0.0.2, but the engineer notices that packets with destination IP 10.0.0.2 itself are also being redirected, causing a loop. Why does this happen?

⚠ Common exam trap

The trap is overlooking that PBR does not exempt traffic destined to the configured next-hop address, so candidates assume the router would process such packets locally rather than forwarding them back out.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The set ip next-hop command does not check if the next-hop is the router itself, so packets destined to the router are forwarded instead of being processed locally.

When PBR uses 'set ip next-hop', the router rewrites the forwarding decision for matched packets without checking whether the next-hop address belongs to the router itself. If the ACL matches traffic destined to the router's own IP (which is also the configured next-hop), the router forwards the packet out toward 10.0.0.2 instead of delivering it to its own control plane, creating a forwarding loop or black hole. The fix is to exclude the next-hop address (and the router's own addresses) from the ACL match.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The ACL 100 inadvertently matches the router's own IP address as source.

    Why it's wrong here

    The ACL matches on destination, not source; the router's own address appears as the destination of traffic directed to it, so the route-map redirects those packets. Source matching would not capture traffic addressed to 10.0.0.2. Excluding the next-hop address from the ACL prevents the loop.

  • ✗

    PBR is applied outbound, causing packets to the router to be re-routed.

    Why it's wrong here

    PBR is applied inbound on GigabitEthernet0/1, not outbound; outbound application would affect traffic leaving an interface, but the loop occurs because inbound PBR on the receiving interface intercepts packets destined for the router’s own IP (10.0.0.2) before the local delivery decision, redirecting them back out. This option is tempting because outbound PBR is commonly used to influence forwarding of transit traffic, and an engineer might misattribute the loop to a misapplied direction rather than recognising that PBR overrides the router’s local route for its own IP address.

  • ✓

    The set ip next-hop command does not check if the next-hop is the router itself, so packets destined to the router are forwarded instead of being processed locally.

    Why this is correct

    Policy-based routing rewrites the next hop before the packet is tested against the local forwarding table, and the set ip next-hop action does not verify whether that address belongs to the router itself. Traffic destined for 10.0.0.2 is therefore redirected out of the interface rather than delivered locally, producing the loop.

  • ✗

    The route-map has a default route that sends all traffic to 10.0.0.2.

    Why it's wrong here

    ACL 100 presumably permits all traffic, so the destination 10.0.0.2 matches and is redirected to itself, looping. The route-map contains no default route; a default route is a routing-table entry, not a route-map clause. A default route would be relevant only when no specific route exists.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

One of 1,401 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.