mediumMultiple Select
350-401 Practice Question: Which two statements about MPLS VPN (Layer 3 VPN)…
Which two statements about MPLS VPN (Layer 3 VPN) are true? (Choose two.)
⚠ Common exam trap
350-401 often tests whether candidates confuse the roles of P, PE, and CE routers, and candidates frequently think P routers need per-VPN tables or that CE routers run MPLS, which is incorrect.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
PE routers maintain separate VRF tables for each VPN customer.
Option A is correct because in an MPLS Layer 3 VPN, each PE router instantiates a separate VRF (Virtual Routing and Forwarding) table per customer VPN, which keeps customer routes isolated and allows overlapping address spaces. Option C is correct because PE routers use MP-BGP (Multiprotocol BGP, specifically the VPNv4 address family) to exchange customer routes with the appropriate route targets and VPN labels. Option B is wrong because P routers only need to forward labeled packets based on the outer IGP/LDP label and do not hold per-VPN customer routing tables. Option D is wrong because CE routers are typically plain IP routers that do not run MPLS or exchange labels with the PE. Option E is wrong because the inner VPN label is used by the egress PE (not the P routers) to identify the customer VRF; P routers forward based on the outer transport label.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
PE routers maintain separate VRF tables for each VPN customer.
Why this is correct
Each PE router holds a separate VRF table per VPN customer, isolating that customer's routes and forwarding decisions. This satisfies the stem's Layer 3 VPN requirement by preventing overlapping customer address space from colliding, keeping each VPN's traffic logically separate across the shared provider backbone.
- ✗
P routers must maintain a full routing table for each VPN customer.
Why it's wrong here
P routers forward labelled packets using only the provider's IGP and label-switching table; per-VPN routing tables live on PE routers, isolated by VRFs. Requiring them on P routers would defeat MPLS's scalability. This option tempts because VRF separation is genuinely central to Layer 3 VPNs — but that responsibility sits at the provider edge, not the core.
- ✓
MP-BGP is used to exchange VPNv4 routes between PE routers.
Why this is correct
MP-BGP carries VPNv4 routes between PE routers, using route targets to identify which VPN each prefix belongs to. This satisfies the stem's Layer 3 VPN requirement by distributing customer routes across the provider backbone while keeping separate customers' reachability information distinct.
- ✗
CE routers run MPLS and participate in label distribution with the PE.
Why it's wrong here
In an MPLS Layer 3 VPN, the CE router sits outside the provider's MPLS domain and does not run MPLS or exchange labels; the PE router performs label distribution and VRFs. This option would fit a CsC or inter-AS carrier-supporting-carrier design, where the CE itself is a provider edge device.
- ✗
The VPN label is used by P routers to forward traffic across the MPLS core.
Why it's wrong here
The VPN label is swapped and processed by PE routers at the edge of the MPLS domain; P routers forward on the outer transport label only, never reading the VPN label. It is tempting because labels do direct core forwarding, but that role belongs to the LDP or RSVP transport label.
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.