hardMultiple SelectObjective-mapped
300-410 Practice Question: An engineer is troubleshooting a VRF-Lite setup…
An engineer is troubleshooting a VRF-Lite setup where two VRFs (BLUE and RED) are configured on a router. Hosts in VRF BLUE cannot ping the default gateway of VRF RED. Which TWO statements correctly explain why this is expected behavior? (Choose TWO.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Each VRF maintains its own separate routing table, so VRF BLUE has no route to the subnet of VRF RED.
VRF-Lite provides complete isolation between VRFs at Layer 3. By default, no traffic can flow between VRFs unless explicit inter-VRF routing is configured (e.g., using a router with two interfaces in different VRFs or using route leaking). Option A is correct because VRFs maintain separate routing tables. Option C is correct because by default, a router does not forward packets between VRFs. Option B is incorrect because ARP is per-interface, but the issue is routing, not ARP. Option D is incorrect because the default gateway is reachable within its own VRF. Option E is incorrect because the ping fails due to routing, not because of a missing default route in the source VRF.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Each VRF maintains its own separate routing table, so VRF BLUE has no route to the subnet of VRF RED.
Why this is correct
Correct. VRFs have isolated routing tables; without inter-VRF routing, there is no path.
- ✗
The ARP cache in VRF BLUE does not contain the MAC address of the VRF RED gateway.
Why it's wrong here
Incorrect. ARP is per-interface; the host in BLUE would ARP for its own gateway, not for the RED gateway. The failure is due to routing, not ARP.
- ✓
By default, a router does not forward packets between different VRFs unless inter-VRF routing is explicitly configured.
Why this is correct
Correct. VRF-Lite inherently isolates traffic; inter-VRF forwarding requires additional configuration (e.g., route leaking or a router with interfaces in both VRFs).
- ✗
The default gateway in VRF RED is not reachable from VRF BLUE because the gateway interface is in a different VRF.
Why it's wrong here
Incorrect. The gateway is reachable within its own VRF; the issue is that VRF BLUE cannot route to the RED subnet.
- ✗
The ping fails because VRF BLUE does not have a default route pointing to the VRF RED gateway.
Why it's wrong here
Incorrect. Even with a default route, VRF BLUE cannot forward packets to a different VRF without inter-VRF routing.
Go deeper
Related to this question
About these practice questions
One of 1,966 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.