Courseiva
hardMultiple SelectObjective-mapped

MPLS L3VPN: VRF, Route Distinguisher, and Route Target Concepts

Which three statements about MPLS VPN (Layer 3 VPN) are true? (Choose three.)

Quick Answer

The answer is that route targets (RTs) control the import and export of routes between VRFs, which is a foundational truth for MPLS L3VPN. This is correct because in an MPLS Layer 3 VPN, Provider Edge (PE) routers maintain separate VRF instances for each customer, and while route distinguishers (RDs) make overlapping customer prefixes globally unique, it is the RTs that actually govern which routes are shared between VRFs and which are kept isolated. On the ENCOR 350-401 exam, this concept tests your understanding of the control plane separation in MPLS VPNs, often appearing in a "choose three" format where common traps include assuming P routers maintain customer routes or that only one MPLS label is used. Remember that P routers are label-switching only and never see the customer IP routes. A solid memory tip: think of the RD as the "ID card" making each prefix unique, and the RT as the "invitation list" controlling who gets to see it.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

PE routers maintain separate VRF instances for each customer.

In MPLS Layer 3 VPNs, the PE routers maintain separate VRF instances for each customer. Route distinguishers (RDs) make overlapping customer prefixes unique, while route targets (RTs) control the import/export of routes between VRFs. The P (provider) routers do not need to know about customer routes; they only switch based on MPLS labels. Option D is incorrect because P routers do not maintain customer routes. Option E is incorrect because MPLS VPNs use two labels: the inner label identifies the egress PE, and the outer label is used for transport through the core.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • PE routers maintain separate VRF instances for each customer.

    Why this is correct

    Correct because VRFs isolate customer routing tables on the PE.

  • Route distinguishers (RDs) are used to make overlapping customer prefixes unique.

    Why this is correct

    Correct because RDs prepend a 64-bit value to create unique VPNv4 prefixes.

  • Route targets (RTs) control the import and export of routes between VRFs.

    Why this is correct

    Correct because RTs are BGP extended communities that govern route distribution.

  • P routers must maintain customer VPN routing information.

    Why it's wrong here

    Incorrect because P routers only switch MPLS labels and do not need customer routes.

  • MPLS VPNs use a single label to forward packets across the service provider core.

    Why it's wrong here

    Incorrect because MPLS VPNs use two labels: an outer transport label and an inner VPN label.

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,175 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on 350-401

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which two statements about MPLS VPN (Layer 3 VPN) are true? (Choose two.)

medium
  • A.PE routers maintain separate VRF tables for each VPN customer.
  • B.P routers must maintain a full routing table for each VPN customer.
  • C.MP-BGP is used to exchange VPNv4 routes between PE routers.
  • D.CE routers run MPLS and participate in label distribution with the PE.
  • E.The VPN label is used by P routers to forward traffic across the MPLS core.

Why A: In MPLS Layer 3 VPNs, the PE router maintains separate VRF tables per customer and uses MP-BGP to exchange VPNv4 routes (including the route distinguisher and VPN label). The P router does not need to know customer routes; it only swaps labels. The CE router does not participate in MPLS; it runs standard IP routing with the PE.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.