350-401 Virtualization Practice Question
A service provider uses a Cisco ASR 1000 router to provide MPLS L3VPN services to multiple customers. Each customer has their own VRF. Recently, a new customer was added with VRF CUSTOMER_C. After configuration, the customer reports that they can reach some remote sites but not others. The network engineer checks the VRF configuration and finds that the route targets for CUSTOMER_C are correctly configured. The engineer also verifies that BGP sessions to the PE routers are up. The missing routes are from a site that uses a different PE router. Which action should the engineer take to resolve the issue?
⚠ Common exam trap
Cisco often tests the misconception that route target configuration is only needed on one PE, or that BGP session status alone guarantees route exchange, when in fact both import and export RTs must match across all PEs participating in the same VRF.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Verify that the route target import/export values on the remote PE match those on the local PE for VRF CUSTOMER_C.
The issue is that the remote PE router does not have the correct route target import/export configuration for VRF CUSTOMER_C. In MPLS L3VPN, VRFs on different PEs must have matching route target values to import and export VPNv4 routes into the correct VRF. Even if the local PE is correctly configured, the remote PE must also import the routes from the local PE using the same route target. Without this, the remote PE will not install the VPNv4 prefixes into its VRF, causing the customer to be unable to reach sites connected to that remote PE.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Increase the MTU on the link between the PE routers.
Why it's wrong here
Increasing the MTU on the PE link would only affect the MPLS data plane, typically causing large packets to be dropped or fragmented when the link MTU is smaller than the imposed label stack. The symptom described—an absent route within a specific VRF—is a control-plane issue: MTU errors do not prevent BGP from exchanging VPNv4 routes or influence the route-target import logic. If MTU were truly the problem, you would see packet loss or PMTU failures for traffic to multiple prefixes, not a missing entry in the VRF table.
- ✗
Reconfigure LDP on the PE routers to establish a targeted session.
Why it's wrong here
LDP (both link-local and targeted) builds label bindings for IGP prefixes in the core, enabling label-switched paths for transport; it has no role in the import or export of VPNv4 routes into a VRF. The presence of a VPNv4 route in a VRF is governed by MP-BGP and the route-target extended community, not by LDP. A targeted LDP session is relevant for topologies like inter-AS Option B or Layer 2 VPNs, but would not cause a single VRF route to be absent; without LDP, the MPLS core would lack a transport label, but the VPNv4 control plane would still operate.
- ✗
Check the MPLS label stack on the local PE to ensure labels are being swapped correctly.
Why it's wrong here
Checking the MPLS label stack on the local PE is a data-plane diagnostic; if the label were being swapped incorrectly, the forwarded packets would be misrouted or dropped for every destination using that LSP. Since the issue is isolated to a single VRF's route table, a label-forwarding anomaly would be an unlikely cause and would not explain why the route was not installed in the VRF. Moreover, the local PE's operation of swapping a received label is irrelevant to whether the remote PE imported the VPNv4 route; the remote PE's import decision happens before any label is imposed.
- ✓
Verify that the route target import/export values on the remote PE match those on the local PE for VRF CUSTOMER_C.
Why this is correct
In MPLS Layer 3 VPNs, each VRF is configured with import and export route targets; a received VPNv4 route is installed into a VRF only if its route-target list matches one of the VRF's import targets. If the export RT on the advertising PE does not match the import RT configured in the remote PE for VRF CUSTOMER_C, the route is accepted into the BGP VPNv4 table but silently filtered out of the VRF. Verifying and correcting the RT values to be consistent on both PEs is the requisite fix, as this is the control-plane mechanism responsible for the observed missing route.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.