Courseiva
mediumMultiple Choice

300-410 Practice Question: Consider the following configuration on R5: !---…

Consider the following configuration on R5:

!--- R5 configuration

ip prefix-list PL-2 seq 5 permit 10.0.0.0/8 ge 16 le 24

! route-map RMAP permit 10 match ip address prefix-list PL-2 set community 100:100 !

router bgp 65200
 neighbor 192.168.1.2 route-map RMAP out

!

What is the effect of this configuration?

⚠ Common exam trap

The trap here is assuming that a route-map with a match clause only sets attributes on matching routes but still permits all routes; however, a route-map used as a filter implicitly denies unmatched routes, so only matching routes are sent.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Only routes with prefix 10.0.0.0/8 and mask length between 16 and 24 are sent to neighbor with community 100:100.

The prefix-list PL-2 permits 10.0.0.0/8 with a mask length between 16 and 24 (ge 16 le 24). The route-map RMAP matches this prefix-list and sets community 100:100. Since the route-map is applied outbound to neighbor 192.168.1.2, only routes that match the prefix-list are permitted by the route-map (implicit deny at the end of the route-map), and those matching routes are sent with community 100:100. Therefore, only routes with prefix 10.0.0.0/8 and mask length between 16 and 24 are sent, and they are tagged with community 100:100.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Only routes with prefix 10.0.0.0/8 and mask length between 16 and 24 are sent to neighbor with community 100:100.

    Why this is correct

    The prefix-list matches 10.0.0.0/8 with mask lengths from /16 to /24 inclusive, so only those more-specific subnets satisfy the route-map's match clause. Routes passing it are advertised to 192.168.1.2 with community 100:100 set; the /8 itself and anything outside that range is denied.

  • ✗

    All routes with prefix 10.0.0.0/8 are sent to neighbor; routes with mask length between 16 and 24 get community 100:100.

    Why it's wrong here

    The prefix-list uses ge 16 le 24, so only routes with masks from /16 to /24 match and receive the community; the /8 itself is excluded. It is tempting because the permit entry names 10.0.0.0/8, and without ge/le that network alone would match and be advertised with community 100:100.

  • ✗

    Routes that match the prefix-list are sent with community 100:100; all other routes are sent without any community.

    Why it's wrong here

    The route-map has a single permit sequence matching PL-2, so non-matching prefixes hit the implicit deny and are not advertised to 192.168.1.2 at all. The option is tempting because route-maps without a set clause pass routes unchanged, but here the match failure drops them rather than sending them community-free.

  • ✗

    The configuration is invalid because the prefix-list uses ge and le together; only one can be used.

    Why it's wrong here

    Cisco prefix-lists accept ge and le together: ge sets the minimum prefix length, le the maximum, so 10.0.0.0/8 ge 16 le 24 matches all subnets of 10.0.0.0/8 with masks from /16 to /24. The option is tempting because ge and le are mutually exclusive in some other vendors' prefix filters, but IOS permits both.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every 300-410 question from scratch — 1,401 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on 300-410

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Consider the following configuration on router R2: !--- R2 configuration ip prefix-list FILTER seq 5 deny 10.1.0.0/16 le 24 ip prefix-list FILTER seq 10 permit 0.0.0.0/0 le 32 ! route-map BGP-IN permit 10 match ip address prefix-list FILTER ! router bgp 65000 neighbor 192.168.1.1 route-map BGP-IN in ! What is the effect of this configuration?

medium
  • A.All routes from neighbor 192.168.1.1 are accepted; the prefix-list is not applied correctly because the route-map only has a permit sequence.
  • ✓ B.Routes within 10.1.0.0/16 with mask length 24 or shorter are denied; all other routes are permitted.
  • C.Only routes with mask length exactly 24 are denied; all other routes are permitted.
  • D.The configuration is incomplete; a route-map must have a deny statement to filter routes.

Why B: The prefix-list FILTER denies any prefix within 10.1.0.0/16 with a mask length less than or equal to 24 (i.e., 10.1.0.0/16 through 10.1.255.0/24). The permit statement allows all other prefixes. The route-map BGP-IN calls this prefix-list; since there is only one permit sequence, routes that match the deny statement in the prefix-list are implicitly denied by the route-map. Therefore, routes like 10.1.0.0/16, 10.1.1.0/24, etc., are filtered out.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.