Courseiva
mediumMultiple Choice

350-401 Practice Question: Router bgp 65000 bgp router-id 10.0.0.1 neighbor…

router bgp 65000

bgp router-id 10.0.0.1

neighbor 10.0.0.2 remote-as 65001
 neighbor 10.0.0.2 route-map FILTER in

! route-map FILTER deny 10 match ip address prefix-list BLOCKED route-map FILTER permit 20 !

ip prefix-list BLOCKED seq 5 permit 10.0.0.0/8

! What is the effect of this configuration?

⚠ Common exam trap

Cisco often tests the interaction between route-map sequence numbers and the implicit deny at the end of a route-map, leading candidates to forget that a permit statement with no match (like sequence 20) is needed to allow all other routes through.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

All routes from neighbor 10.0.0.2 are accepted except those matching 10.0.0.0/8.

The route-map FILTER is applied inbound from neighbor 10.0.0.2. Sequence 10 denies routes that match the prefix-list BLOCKED, which permits 10.0.0.0/8. Sequence 20 is a permit statement with no match, which implicitly permits all other routes. Therefore, only routes matching 10.0.0.0/8 are denied, and all other routes are accepted.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    All routes from neighbor 10.0.0.2 are accepted except those matching 10.0.0.0/8.

    Why this is correct

    The route-map is evaluated in ascending sequence order, and each BGP route is checked against the clauses. The first clause is a deny statement that matches the prefix-list for 10.0.0.0/8, so any route within that aggregate is rejected. The subsequent permit clause with no match conditions acts as a catch-all, allowing every other route. Thus, only routes that fall under 10.0.0.0/8 are filtered, while all other prefixes from the neighbor are accepted.

  • ✗

    Only routes matching 10.0.0.0/8 are accepted from the neighbor.

    Why it's wrong here

    This option incorrectly reverses the effect of the deny and permit clauses. Because the deny clause is listed first, it explicitly blocks routes matching 10.0.0.0/8 from being installed. The later permit clause only accepts the remaining routes, meaning the specific prefix is excluded rather than being the sole accepted set. If the intent were to accept only that prefix, the deny and permit logic would need to be inverted, which is not the case here.

  • ✗

    The configuration is invalid because route-map must have a permit statement first.

    Why it's wrong here

    There is no rule requiring a route-map to begin with a permit statement. Route-maps are processed sequentially, and the action (permit or deny) is applied to the first matched clause. Starting with a deny clause is a standard and valid technique for selectively filtering prefixes. The implicit deny at the end of every route-map already handles unmatched routes, so an explicit initial deny is not a configuration error.

  • ✗

    The prefix-list is misconfigured because it should use 'deny' instead of 'permit'.

    Why it's wrong here

    The prefix-list is correctly using 'permit' because it serves only as a match condition; it does not itself filter BGP routes. In the route-map, the deny clause references this prefix-list to identify which routes should be filtered. The actual decision to reject the prefix is made by the route-map's deny action, not by the prefix-list's permit. Changing the prefix-list to 'deny' would still match the same prefix, but the route-map denial would then be nonsensical, and this misunderstanding reflects a failure to separate the match and action phases.

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.