Courseiva
easyMultiple Choice

300-410 Practice Question: The default action for a packet that does not…

What is the default action for a packet that does not match any route-map entry in a PBR policy?

⚠ Common exam trap

The trap is conflating the implicit deny behavior of route-maps in redistribution (where unmatched routes are filtered) with PBR (where unmatched packets fall through to normal routing) — candidates who assume 'implicit deny = drop' pick option A.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The packet is forwarded using the routing table.

Policy-Based Routing (PBR) via route-maps uses an implicit deny at the end of the route-map, but 'deny' in a route-map used for PBR means 'do not policy-route this packet' — the packet is then forwarded normally using the routing table. This differs from route-maps used for route redistribution, where an implicit deny means the route is not redistributed. The key distinction is the context: PBR route-maps fall through to normal destination-based forwarding.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The packet is dropped.

    Why it's wrong here

    Unmatched packets are not dropped; PBR is not an implicit deny, so the router forwards them using the normal routing table. It is tempting because ACLs do drop unmatched traffic, but route-maps used for policy routing behave differently.

  • ✓

    The packet is forwarded using the routing table.

    Why this is correct

    Policy-based routing evaluates route-map entries sequentially; if no entry matches the packet, PBR yields and normal destination-based forwarding resumes. The packet is therefore routed via the routing table, which is the default behaviour when no policy statement applies.

  • ✗

    The packet is sent to the CPU for processing.

    Why it's wrong here

    PBR does not punt unmatched packets to the CPU; the route-map is evaluated, and if no entry matches, normal destination-based routing proceeds. It is tempting because CPU punting occurs for control-plane or exception traffic, not for policy-routing misses.

  • ✗

    The router sends an ICMP unreachable message.

    Why it's wrong here

    No ICMP unreachable is generated on a route-map miss; the packet simply falls through to the routing table. It is tempting because unreachables are emitted when no route exists at all, which is a different condition from a policy entry not matching.

Go deeper

Related to this question

About these practice questions

This 300-410 question is part of Courseiva's 1,401-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.