Courseiva
Architecture →mediumMultiple Choice

350-401 Architecture Practice Question

A company is deploying a WAN with MPLS VPN and wants to ensure that customer traffic is isolated from other customers. Which technology is used to maintain separation in the MPLS core?

⚠ Common exam trap

Cisco often tests the misconception that MPLS labels alone provide customer separation, but labels are only a forwarding mechanism; the actual isolation comes from VRF instances on the PE routers.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Virtual Routing and Forwarding (VRF)

VRF (Virtual Routing and Forwarding) is the technology used in MPLS VPN to maintain customer traffic separation within the MPLS core. Each customer is assigned a unique VRF on the Provider Edge (PE) router, which maintains a separate routing table and forwarding instance, ensuring that traffic from one customer never crosses into another customer's routing domain. This separation is enforced at Layer 3, independent of the MPLS label switching that occurs in the core.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    VLAN tagging

    Why it's wrong here

    VLAN tagging operates at Layer 2 by inserting a 12-bit tag into the Ethernet frame header to segment broadcast domains on a local switch. In an MPLS VPN core, VLAN IDs are only relevant on access or trunk links to the PE (Provider Edge) router and do not extend across the provider backbone. Because VLANs don't create separate Layer 3 routing tables, they cannot isolate routing information between VPN customers in the MPLS core. Even if customer edges are on different VLANs, the PE still uses a single global routing table unless VRF is explicitly configured, so VLAN tagging alone is insufficient for ensuring inter-customer isolation.

  • ✗

    MPLS labels

    Why it's wrong here

    MPLS labels are fixed-length shim headers appended between the Layer 2 header and the IP packet, used solely for forwarding decisions along label-switched paths. The label is swapped by each LSR (Label Switch Router) based on the LIB (Label Information Base) and does not carry any routing or VPN membership information. All VPN customers share the same MPLS core infrastructure and label space, meaning labels do not separate routing tables or filter route advertisement between different VPNs. While labels enable traffic forwarding to the correct CE (Customer Edge), they provide no mechanism to prevent one customer's routes from leaking into another's routing table; that isolation is a function of VRFs at the PE.

  • ✗

    IPsec tunnels

    Why it's wrong here

    IPsec tunnels deliver security services through Authentication Header (AH) or Encapsulating Security Payload (ESP) protocols, providing data integrity, origin authentication, and optionally confidentiality. However, IPsec operates at the network layer in terms of encryption and does not influence how routing tables are constructed or how routes are shared between customers. An IPsec VPN can protect traffic between sites, but if the underlay or overlay uses a shared routing protocol without VRF, routes from different customers could still intermingle. Thus, IPsec only secures the transport path; it cannot create separate routing instances or enforce routing isolation between customers in an MPLS L3VPN service.

  • ✓

    Virtual Routing and Forwarding (VRF)

    Why this is correct

    Virtual Routing and Forwarding (VRF) creates separate, independent IP routing tables and associated forwarding tables on the Provider Edge (PE) router. Each VRF instance contains its own set of routes, interfaces, and routing protocol processes, ensuring that customer A's routing information is completely invisible to customer B. This table separation is how an MPLS L3VPN achieves routing isolation, even though both customers share the same physical backbone. When combined with route distinguishers (RDs) and route targets (RTs), VRF controls the import and export of routes into the VPN, thereby maintaining strict logical isolation across a shared MPLS core.

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.