hardMultiple Choice
300-410 Practice Question: Router R1 is leaking a summary route 10.0.0.0/8…
Router R1 is leaking a summary route 10.0.0.0/8 from VRF-A into the global routing table, but hosts in the global table cannot reach subnet 10.1.1.0/24 within VRF-A. R1 configuration: ip vrf VRF-A, rd 100:1, route-target export 100:1, route-target import 100:1. Interface Gig0/0 in VRF-A has ip address 10.1.1.1 255.255.255.0. The leaking is done via route-map: route-map LEAK permit 10, match ip address prefix-list SUMMARY, set global. Prefix-list SUMMARY permits 10.0.0.0/8. What is the root cause?
⚠ Common exam trap
The trap is assuming that leaking a summary route automatically carries the more-specific subnets with it — in IOS, each prefix must independently match the export route-map, so a /8 leak does not include a /24.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The summary route 10.0.0.0/8 is being installed in the global table, but the more specific route 10.1.1.0/24 is not leaked, causing traffic to be dropped.
The prefix-list SUMMARY only permits 10.0.0.0/8, so only the aggregate is leaked into the global table. The more specific 10.1.1.0/24 remains inside VRF-A and is never exported, so global-table hosts match the /8 and forward traffic toward R1, but R1 has no /24 in the global RIB and drops the packets. Leaking a summary without the constituent specifics creates a black hole for every subnet inside the aggregate.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The summary route 10.0.0.0/8 is being installed in the global table, but the more specific route 10.1.1.0/24 is not leaked, causing traffic to be dropped.
Why this is correct
The global table only receives the /8 summary, which is not a valid forwarding path for 10.1.1.0/24 inside VRF-A; the /24 is never leaked, so return traffic has no matching global entry and is dropped.
- ✗
The route-map should use match ip address prefix-list SPECIFIC instead of SUMMARY.
Why it's wrong here
Matching the specific 10.1.1.0/24 would leak only that subnet, not the required 10.0.0.0/8 summary. The SUMMARY prefix-list is correct for the stated leak; the fault lies in the VRF's connected subnet not being redistributed into BGP for the global table to resolve.
- ✗
The VRF must have a default route to reach the global table.
Why it's wrong here
VRF leaking via the set global route-map action does not require a default route inside the VRF; the summary 10.0.0.0/8 is exported with its next hop already resolved in the global table. A default route matters only when the VRF itself needs to originate traffic toward destinations outside it.
- ✗
The prefix-list should permit 10.1.1.0/24 only.
Why it's wrong here
Permitting only 10.1.1.0/24 contradicts the requirement to leak the 10.0.0.0/8 summary. The prefix-list correctly matches the summary; the actual fault is that the VRF's connected 10.1.1.0/24 is not present in BGP, so the leaked summary has no valid path.
Visual reference
Go deeper
Related to this question
Learn chapter
OSPF Route Summarization and Filtering
Key term
BGP Prefix Filtering
BGP Prefix Filtering is the practice of controlling which network routes (prefixes) a router accepts or advertises to its BGP neighbors, preventing unwanted or harmful routes from spreading across the internet.
Key term
MPLS Layer 3 VPN
A technology that uses Multiprotocol Label Switching to create secure, scalable virtual private networks that connect multiple sites at the network layer, where the service provider manages routing between customer sites.
About these practice questions
This 300-410 question is part of Courseiva's 1,401-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.