350-401 Architecture Practice Question
A company is deploying an MPLS VPN to connect multiple branch sites to a central data center. The network engineer must ensure that customer traffic is isolated from other customers and that routing information is kept separate. Which two statements are correct about MPLS Layer 3 VPNs? (Choose two.)
⚠ Common exam trap
Test-takers frequently confuse route targets with the mechanism that identifies the VRF for packet forwarding; route targets control route distribution, not packet classification.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
VRF instances on PE routers provide logical separation of customer routing tables.
MPLS Layer 3 VPNs rely on VRF instances on PE routers to separate customer routing tables and MP-BGP to distribute VPNv4 routes across the provider backbone. Route targets control route import/export, but they do not identify the VRF for packet forwarding. The label stack typically has two labels. CE routers do not run MP-BGP; they run standard routing protocols with the PE. Thus, the correct statements are about VRF separation and MP-BGP route distribution.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Route targets are used to identify the VRF on the PE router that a packet belongs to.
Why it's wrong here
Route targets (RTs) are extended BGP communities used to control the import and export of routes between VRFs. They do not identify the VRF for packet forwarding; that is done by the MPLS label and the incoming interface. RTs determine which routes are imported into which VRF. Confusing RTs with the forwarding mechanism is a common error, but RTs are for route distribution control, not packet classification.
- ✗
Customer edge routers must run MP-BGP with the provider edge routers to exchange VPN routes.
Why it's wrong here
Customer edge (CE) routers typically run standard routing protocols such as OSPF, EIGRP, or BGP with the provider edge (PE) routers, but they do not need to run MP-BGP. MP-BGP is used between PE routers within the provider network. The CE router is unaware of the MPLS VPN infrastructure. Requiring MP-BGP on CE routers would be incorrect and is not a requirement for MPLS Layer 3 VPNs.
- ✓
VRF instances on PE routers provide logical separation of customer routing tables.
Why this is correct
VRF (Virtual Routing and Forwarding) instances create separate routing and forwarding tables on PE routers. Each customer is assigned its own VRF, so routes from one customer are not leaked into another's table. This logical separation is fundamental to MPLS Layer 3 VPNs and ensures traffic isolation. The VRF also allows overlapping IP address spaces between customers, which is a key benefit of MPLS VPNs.
- ✗
The MPLS label stack consists of only a single label for all VPN traffic.
Why it's wrong here
MPLS VPN traffic typically uses a two-label stack: the top label is the transport label used by the backbone routers to forward the packet to the egress PE, and the bottom label is the VPN label that identifies the customer VRF or the egress interface on the PE. A single label would not provide the necessary separation and forwarding information. Therefore, this statement is incorrect.
- ✓
MP-BGP is used to distribute customer routes across the MPLS backbone.
Why this is correct
Multiprotocol BGP (MP-BGP) is the routing protocol used to exchange customer routes between PE routers. It carries the VPNv4 address family, which includes the route distinguisher to keep customer routes unique. MP-BGP allows the PE routers to advertise and learn routes for different VRFs, enabling end-to-end connectivity across the MPLS backbone. It is essential for MPLS Layer 3 VPN operation.
Quick reference
Routing Protocol Comparison
| Protocol | Metric | Max Hops | Algorithm | Type |
|---|---|---|---|---|
| RIP v2 | Hop count | 15 | Bellman-Ford | Distance vector |
| OSPF | Cost (bandwidth) | Unlimited | Dijkstra (SPF) | Link state |
| EIGRP | Composite metric | Unlimited | DUAL | Hybrid |
| IS-IS | Cost | Unlimited | Dijkstra | Link state |
| BGP | Policy / attributes | Unlimited | Path vector | Path vector |
RIP's 15-hop limit makes it unsuitable for large networks. OSPF and EIGRP dominate modern enterprise deployments.
Go deeper
Related to this question
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.