mediumMultiple Select
300-410 Practice Question: Which TWO statements are true regarding the use…
Which TWO statements are true regarding the use of VRF-Lite in a Cisco Enterprise network? (Choose TWO.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
VRF-Lite enables multiple virtual routing tables on a single router, providing traffic separation without MPLS.
VRF-Lite allows multiple routing tables on a single router, enabling traffic separation without MPLS. It relies on static routes or dynamic routing protocols like OSPF, EIGRP, or BGP within each VRF. The incorrect options: MPLS is not required for VRF-Lite; VRF-Lite does not support MPLS VPNv4 route exchange (that requires MPLS); and VRF-Lite does not inherently provide encryption.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
VRF-Lite enables multiple virtual routing tables on a single router, providing traffic separation without MPLS.
Why this is correct
VRF-Lite creates independent routing and forwarding tables on one physical router, each with its own interfaces and routes. Traffic between VRFs stays isolated without MPLS labels or VPNv4 address families, satisfying the question's requirement for separation without MPLS.
- ✓
VRF-Lite supports dynamic routing protocols such as OSPF and EIGRP within each VRF.
Why this is correct
VRF-Lite is VRF functionality without MPLS label distribution, so each VRF runs its own routing instance. OSPF and EIGRP neighbours form independently per VRF over separate subinterfaces, giving the per-VRF dynamic routing the statement asserts.
- ✗
VRF-Lite requires MPLS to exchange VPNv4 routes between routers.
Why it's wrong here
VRF-Lite keeps VRFs local to a device, using 802.1Q subinterfaces or GRE to extend them; no MPLS label stack or VPNv4 address family is involved. It is tempting because MPLS L3VPN does require VPNv4 route exchange, but that is a separate, label-switching technology, not VRF-Lite.
- ✗
VRF-Lite can automatically encrypt traffic between VRFs using IPsec.
Why it's wrong here
VRF-Lite provides traffic separation at Layer 3 only; it performs no encryption, and IPsec must be configured separately on the underlying links. It is tempting because VRF-Lite is often paired with IPsec over untrusted transport, but the encryption comes from IPsec, not from VRF-Lite itself.
- ✗
VRF-Lite can only be used with static routing.
Why it's wrong here
VRF-Lite supports any routing protocol per VRF, including OSPF, EIGRP and BGP, not static routes alone. The temptation arises because static routes are the simplest way to populate a small VRF, but the technology itself is routing-protocol agnostic and commonly runs OSPF or BGP within each VRF.
Visual reference
Quick reference
Routing Protocol Comparison
| Protocol | Metric | Max Hops | Algorithm | Type |
|---|---|---|---|---|
| RIP v2 | Hop count | 15 | Bellman-Ford | Distance vector |
| OSPF | Cost (bandwidth) | Unlimited | Dijkstra (SPF) | Link state |
| EIGRP | Composite metric | Unlimited | DUAL | Hybrid |
| IS-IS | Cost | Unlimited | Dijkstra | Link state |
| BGP | Policy / attributes | Unlimited | Path vector | Path vector |
RIP's 15-hop limit makes it unsuitable for large networks. OSPF and EIGRP dominate modern enterprise deployments.
Go deeper
Related to this question
Learn chapter
VRF-Lite and Multi-Protocol BGP
Key term
MP-BGP for VPN
MP-BGP for VPN is an extension of the Border Gateway Protocol that carries multiple types of network layer information to enable scalable, isolated virtual private networks over a shared provider infrastructure.
Key term
MPLS Layer 3 VPN
A technology that uses Multiprotocol Label Switching to create secure, scalable virtual private networks that connect multiple sites at the network layer, where the service provider manages routing between customer sites.
About these practice questions
This 300-410 question is part of Courseiva's 1,401-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.