Courseiva
mediumMultiple Select

350-401 Practice Question: Which two statements about MPLS VPN (Layer 3 VPN)…

Which two statements about MPLS VPN (Layer 3 VPN) are true? (Choose two.)

⚠ Common exam trap

350-401 often tests whether candidates confuse the roles of P, PE, and CE routers, and candidates frequently think P routers need per-VPN tables or that CE routers run MPLS, which is incorrect.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

PE routers maintain separate VRF tables for each VPN customer.

Option A is correct because in an MPLS Layer 3 VPN, each PE router instantiates a separate VRF (Virtual Routing and Forwarding) table per customer VPN, which keeps customer routes isolated and allows overlapping address spaces. Option C is correct because PE routers use MP-BGP (Multiprotocol BGP, specifically the VPNv4 address family) to exchange customer routes with the appropriate route targets and VPN labels. Option B is wrong because P routers only need to forward labeled packets based on the outer IGP/LDP label and do not hold per-VPN customer routing tables. Option D is wrong because CE routers are typically plain IP routers that do not run MPLS or exchange labels with the PE. Option E is wrong because the inner VPN label is used by the egress PE (not the P routers) to identify the customer VRF; P routers forward based on the outer transport label.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    PE routers maintain separate VRF tables for each VPN customer.

    Why this is correct

    Each PE router holds a separate VRF table per VPN customer, isolating that customer's routes and forwarding decisions. This satisfies the stem's Layer 3 VPN requirement by preventing overlapping customer address space from colliding, keeping each VPN's traffic logically separate across the shared provider backbone.

  • ✗

    P routers must maintain a full routing table for each VPN customer.

    Why it's wrong here

    P routers forward labelled packets using only the provider's IGP and label-switching table; per-VPN routing tables live on PE routers, isolated by VRFs. Requiring them on P routers would defeat MPLS's scalability. This option tempts because VRF separation is genuinely central to Layer 3 VPNs — but that responsibility sits at the provider edge, not the core.

  • ✓

    MP-BGP is used to exchange VPNv4 routes between PE routers.

    Why this is correct

    MP-BGP carries VPNv4 routes between PE routers, using route targets to identify which VPN each prefix belongs to. This satisfies the stem's Layer 3 VPN requirement by distributing customer routes across the provider backbone while keeping separate customers' reachability information distinct.

  • ✗

    CE routers run MPLS and participate in label distribution with the PE.

    Why it's wrong here

    In an MPLS Layer 3 VPN, the CE router sits outside the provider's MPLS domain and does not run MPLS or exchange labels; the PE router performs label distribution and VRFs. This option would fit a CsC or inter-AS carrier-supporting-carrier design, where the CE itself is a provider edge device.

  • ✗

    The VPN label is used by P routers to forward traffic across the MPLS core.

    Why it's wrong here

    The VPN label is swapped and processed by PE routers at the edge of the MPLS domain; P routers forward on the outer transport label only, never reading the VPN label. It is tempting because labels do direct core forwarding, but that role belongs to the LDP or RSVP transport label.

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.