Courseiva
hardMultiple Choice

300-410 Practice Question: Is troubleshooting PBR on a Cisco router where…

A network engineer is troubleshooting PBR on a Cisco router where traffic from subnet 192.168.50.0/24 should be forwarded to next-hop 10.50.50.2. The route map 'PBR-50' is configured with 'match ip address 160' and 'set ip next-hop 10.50.50.2'. The engineer applies the route map to interface GigabitEthernet0/0. The engineer notices that PBR works for traffic from 192.168.50.0/24, but the router is also policy-routing traffic from other subnets that should not be affected. The engineer checks the ACL 160 and confirms it only matches 192.168.50.0/24. What is the most likely cause?

⚠ Common exam trap

300-410 often tests the misconception that a route map sequence without a match statement is ignored — candidates forget that an empty match clause matches all traffic, causing unintended policy routing.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The route map has a sequence with no match condition, which matches all traffic.

A route map sequence with no match condition matches all traffic, so any traffic entering the interface where the route map is applied will be policy-routed to 10.50.50.2 — even subnets that should not be affected. This explains why other subnets are being policy-routed despite ACL 160 correctly matching only 192.168.50.0/24.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The route map has a sequence with no match condition, which matches all traffic.

    Why this is correct

    A route-map sequence containing only a set clause and no match statement matches all traffic, so packets from other subnets also hit the set ip next-hop action. Adding an explicit deny sequence or restricting the match prevents unintended policy routing beyond 192.168.50.0/24.

  • ✗

    The ACL 160 has a 'permit ip any any' statement at the end.

    Why it's wrong here

    An implicit deny any at the end of ACL 160 would prevent other subnets matching, not cause them to be policy-routed; a trailing permit ip any any would. That trailing permit is tempting because it is standard practise in ACLs used for filtering, where an explicit permit keeps management traffic flowing.

  • ✗

    The 'ip policy route-map' command is applied to multiple interfaces, and traffic from other subnets is entering those interfaces.

    Why it's wrong here

    Applying the same route map to additional interfaces would policy-route traffic arriving on them, matching the symptom of other subnets being redirected. It is tempting because interface-level application is the actual PBR mechanism, but the stem states the map is applied to GigabitEthernet0/0 only.

  • ✗

    The router is using CEF switching, and PBR is applied to all traffic regardless of ACL.

    Why it's wrong here

    CEF switching does not bypass route-map match statements; PBR is evaluated per-packet against the ACL regardless of CEF, so non-matching subnets would take the routing table. CEF is tempting because PBR requires it, but CEF changes forwarding mechanics, not match logic.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

One of 1,401 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.