Courseiva
hardMultiple Choice

350-401 Practice Question: Is configuring BGP on a Cisco router that is part…

A network engineer is configuring BGP on a Cisco router that is part of an enterprise network with multiple BGP peers. The router receives routes from two different ISPs. The engineer wants to ensure that only specific prefixes from ISP-A are installed in the routing table, while all other routes from ISP-A are ignored. Additionally, the engineer wants to accept all routes from ISP-B. Which BGP feature should be used on the router for the peering with ISP-A?

⚠ Common exam trap

Cisco often tests the distinction between filtering incoming routes (distribute list or route map) versus originating routes (network statement) or generating defaults (default-information originate), leading candidates to confuse route map with distribute list when both can filter, but the question explicitly asks for the feature that 'should be used' and distribute list is the precise answer for prefix-only filtering without attribute manipulation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Apply a distribute list under the BGP neighbor configuration for ISP-A.

A distribute list applied under the BGP neighbor configuration for ISP-A allows the engineer to filter specific prefixes using an access list or prefix list, ensuring only the desired prefixes are installed in the routing table while all others from ISP-A are ignored. This is the correct tool for inbound route filtering on a per-neighbor basis, as it directly controls which routes are accepted into the BGP table and subsequently the routing table.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Apply a distribute list under the BGP neighbor configuration for ISP-A.

    Why this is correct

    Applying a distribute list under the BGP neighbor configuration for ISP-A creates an inbound path-filtering mechanism that evaluates each incoming BGP update against a referenced prefix list or access list. The distribute list examines only the NLRI's prefix and prefix length, permitting exactly the specified prefixes and silently ignoring all others before any other BGP policy is applied. This is the simplest and most targeted method for the stated requirement, as it does not involve attribute modification or complex conditional logic.

  • ✗

    Configure a network statement under BGP for the desired prefixes.

    Why it's wrong here

    Configuring a network statement under BGP for the desired prefixes is fundamentally an outbound route-origination technique, not an inbound filter. It instructs the local router to advertise into BGP any exact prefix that already exists in its IP routing table, but it has no effect whatsoever on routes received from a BGP peer such as ISP-A. Thus, it cannot be used to filter incoming routes and would not change which prefixes are accepted from the neighbor.

  • ✗

    Use the default-information originate command under BGP.

    Why it's wrong here

    Using the default-information originate command under BGP injects a default route (0.0.0.0/0) into the BGP routing process, typically to attract traffic from or provide connectivity to a peer. It performs no filtering of incoming routes; instead, it generates a single route that originates from the local router. This command is irrelevant to the requirement of permitting only specific prefixes received from ISP-A, as it neither matches nor filters the neighbor's incoming updates.

  • ✗

    Apply a route map to the neighbor using the route-map command in the inbound direction.

    Why it's wrong here

    Applying an inbound route map, whilst capable of filtering routes, is an overly complex mechanism for simply permitting specific prefixes and ignoring all others, as required for ISP-A. Route maps are primarily designed for conditional modification of route attributes, such as setting local preference, MED, or BGP communities, or for more intricate policy-based routing decisions. It would be the correct choice if the requirement involved altering route attributes for specific prefixes, rather than just a straightforward permit/deny based on prefix matching.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.