350-401 Virtualization Practice Question
A network administrator is configuring a Cisco IOS-XE router to support Virtual Routing and Forwarding (VRF). The administrator wants to ensure that traffic from different VRFs can be routed between each other using a shared service VRF. Which VRF feature allows routes to be leaked between VRFs?
⚠ Common exam trap
Many candidates confuse the role of the route distinguisher with that of the route target; the RD makes prefixes unique, while the RT controls import/export.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Route target export and import
Route targets are used to control the import and export of routes between VRFs. By configuring matching route targets on two VRFs, routes can be leaked from one VRF to another. This is the standard method for inter-VRF communication in MPLS L3VPN and VRF-lite environments. Route distinguishers make prefixes unique but do not control leaking.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
VRF forwarding table
Why it's wrong here
The VRF forwarding table (or CEF table) contains the routes for that VRF. It is the result of the routing process, but it does not itself control route leaking. The forwarding table is populated based on the routes installed, which can include leaked routes if route targets are configured. However, the table itself is not the mechanism for leaking.
- ✗
IP routing protocol redistribution
Why it's wrong here
Redistribution can be used to share routes between routing protocols within the same VRF or between VRFs if you use mutual redistribution with route maps. However, it is not the primary VRF feature for route leaking. Redistribution is a general routing tool, whereas route targets are specifically designed for VRF route import/export in MPLS L3VPN and VRF-lite.
- ✗
Route distinguisher
Why it's wrong here
A route distinguisher (RD) is used to make VPNv4 prefixes unique by prepending it to the IPv4 prefix. It does not control import or export of routes between VRFs. The RD is used for MPLS L3VPN to distinguish overlapping prefixes from different VRFs, but it does not enable route leaking. Route leaking is controlled by route targets.
- ✓
Route target export and import
Why this is correct
In VRF-lite or MPLS L3VPN, route targets control the import and export of routes between VRFs. By configuring matching route targets on two VRFs, routes from one VRF can be imported into another. This is the standard method for route leaking between VRFs. It allows controlled communication between VRFs without merging them entirely.
Go deeper
Related to this question
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.