Courseiva
hardMultiple Select

MPLS L3VPN: VRF, Route Distinguisher, and Route Target Concepts

Which three statements about MPLS VPN (Layer 3 VPN) are true? (Choose three.)

Quick Answer

The answer is that route targets (RTs) control the import and export of routes between VRFs, which is a foundational truth for MPLS L3VPN. This is correct because in an MPLS Layer 3 VPN, Provider Edge (PE) routers maintain separate VRF instances for each customer, and while route distinguishers (RDs) make overlapping customer prefixes globally unique, it is the RTs that actually govern which routes are shared between VRFs and which are kept isolated. On the ENCOR 350-401 exam, this concept tests your understanding of the control plane separation in MPLS VPNs, often appearing in a "choose three" format where common traps include assuming P routers maintain customer routes or that only one MPLS label is used. Remember that P routers are label-switching only and never see the customer IP routes. A solid memory tip: think of the RD as the "ID card" making each prefix unique, and the RT as the "invitation list" controlling who gets to see it.

⚠ Common exam trap

350-401 often tests the misconception that P routers participate in customer routing or that MPLS uses a single label — candidates forget the two-label stack and the fact that only PE routers maintain VRFs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

PE routers maintain separate VRF instances for each customer.

Option A is correct because in an MPLS Layer 3 VPN, each PE router maintains separate VRF (Virtual Routing and Forwarding) instances per customer, which keeps customer routing tables isolated on the shared PE device. Option B is correct because a route distinguisher (RD) is prepended to a customer IPv4 prefix to create a unique VPNv4 address, allowing overlapping customer prefixes (such as duplicate 10.0.0.0/8 networks) to coexist in the provider's BGP table. Option C is correct because route targets (RTs) are extended BGP community attributes that control which VRFs import and export specific routes, thereby defining the VPN topology (hub-and-spoke, full mesh, etc.). Option D is not correct because P (provider) routers only forward labeled packets through the core and do not hold customer VPN routing information; that responsibility belongs to PE routers. Option E is not correct because MPLS VPN forwarding typically uses a two-label stack: an outer label (LDP or RSVP-TE) to reach the egress PE and an inner label (VPN label) to identify the customer VRF or next hop.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    PE routers maintain separate VRF instances for each customer.

    Why this is correct

    Each customer's routes are held in a separate VRF routing table on the PE router, isolating overlapping address space per VPN. This per-VRF separation is the core mechanism that keeps customer traffic distinct across the shared MPLS backbone.

  • ✓

    Route distinguishers (RDs) are used to make overlapping customer prefixes unique.

    Why this is correct

    Route distinguishers prepend an 8-byte value to IPv4 prefixes, converting them into unique VPNv4 addresses within MP-BGP. This satisfies the overlapping customer prefix constraint, since two customers may both use 10.0.0.0/8 without collision. RDs identify the VPN instance; route targets, by contrast, control import and export of routes between VRFs.

  • ✓

    Route targets (RTs) control the import and export of routes between VRFs.

    Why this is correct

    Extended community route targets attached to VPNv4 routes determine which VRFs import or export them, controlling VPN membership and topology. This satisfies the requirement for selective route distribution between customer VRFs across the provider network.

  • ✗

    P routers must maintain customer VPN routing information.

    Why it's wrong here

    P routers switch labelled packets through the core and hold only the IGP and transport labels; customer VPN routes live in the PE routers' VRFs. Requiring P routers to store VPN routing information would defeat the scalability that keeps provider core devices free of customer state.

  • ✗

    MPLS VPNs use a single label to forward packets across the service provider core.

    Why it's wrong here

    MPLS VPNs push two labels: an outer transport label for the LSP and an inner VPN label identifying the VRF or customer route. A single label describes plain MPLS forwarding without VPN separation, which is why it cannot carry per-customer routing context.

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on 350-401

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which two statements about MPLS VPN (Layer 3 VPN) are true? (Choose two.)

medium
  • ✓ A.PE routers maintain separate VRF tables for each VPN customer.
  • B.P routers must maintain a full routing table for each VPN customer.
  • ✓ C.MP-BGP is used to exchange VPNv4 routes between PE routers.
  • D.CE routers run MPLS and participate in label distribution with the PE.
  • E.The VPN label is used by P routers to forward traffic across the MPLS core.

Why A: Option A is correct because in an MPLS Layer 3 VPN, each PE router instantiates a separate VRF (Virtual Routing and Forwarding) table per customer VPN, which keeps customer routes isolated and allows overlapping address spaces. Option C is correct because PE routers use MP-BGP (Multiprotocol BGP, specifically the VPNv4 address family) to exchange customer routes with the appropriate route targets and VPN labels. Option B is wrong because P routers only need to forward labeled packets based on the outer IGP/LDP label and do not hold per-VPN customer routing tables. Option D is wrong because CE routers are typically plain IP routers that do not run MPLS or exchange labels with the PE. Option E is wrong because the inner VPN label is used by the egress PE (not the P routers) to identify the customer VRF; P routers forward based on the outer transport label.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.