hardMultiple Select
350-401 Practice Question: Which three statements about MPLS Layer 3 VPNs…
Which three statements about MPLS Layer 3 VPNs are true? (Choose three.)
⚠ Common exam trap
350-401 often tests the RD vs. RT distinction — candidates confuse the RD (uniqueness) with the RT (import/export policy) and incorrectly assume P routers hold VPN routing tables.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Customer edge (CE) routers exchange routing information with provider edge (PE) routers using static routing, RIP, OSPF, EIGRP, or BGP.
Option A is correct because the CE-PE routing relationship is a standard routing adjacency in which the CE router can run static routing, RIP, OSPF, EIGRP, or BGP with the PE router; the PE router then redistributes those routes into the appropriate VRF. Option B is correct because VRF instances on PE routers create separate routing and forwarding tables per VPN customer, which keeps overlapping customer address space isolated. Option C is correct because PE routers use MP-BGP to exchange VPNv4 prefixes, and each VPNv4 route carries a route distinguisher (RD) to make the prefix unique plus route targets (RTs) to control import/export into VRFs. Option D is not correct because P routers in the MPLS core only switch labeled packets and do not maintain customer VPN routing tables; VPN awareness resides at the PE routers. Option E is not correct because route targets are extended BGP community attributes used to control VPN route import and export between VRFs, not to uniquely identify a customer VPN; that uniqueness function is performed by the route distinguisher (RD).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Customer edge (CE) routers exchange routing information with provider edge (PE) routers using static routing, RIP, OSPF, EIGRP, or BGP.
Why this is correct
CE routers peer with PE routers at the IP layer, so any standard routing protocol works across that link: static routes, RIP, OSPF, EIGRP or BGP. The PE router then redistributes these customer routes into MP-BGP for transport across the provider backbone.
- ✓
VRF (Virtual Routing and Forwarding) instances are used on PE routers to maintain separate routing tables for each VPN customer.
Why this is correct
VRF instances on PE routers create per-customer routing and forwarding tables, isolating overlapping address space between tenants. This satisfies the MPLS Layer 3 VPN requirement for traffic separation across a shared provider backbone, since each VRF binds interfaces and MP-BGP route targets to a distinct customer VPN.
- ✓
MP-BGP (Multiprotocol BGP) is used between PE routers to exchange VPNv4 routes, which include an RD and RT.
Why this is correct
PE routers exchange VPNv4 routes through MP-BGP, and each route carries a route distinguisher for uniqueness plus route targets controlling import and export between VRFs. This is the core control-plane mechanism of MPLS Layer 3 VPNs.
- ✗
The MPLS core routers (P routers) maintain full VPN routing tables to forward traffic based on customer IP prefixes.
Why it's wrong here
P routers forward labelled packets through the MPLS core using the label stack and hold no customer VPN routes; VPNv4 prefixes and per-VRF tables reside on PE routers. It is tempting because P routers do carry the core routing information, and would be correct if the question asked which devices forward traffic across the provider backbone.
- ✗
Route targets (RT) are used to uniquely identify each customer VPN across the provider network.
Why it's wrong here
Route targets are BGP extended community attributes that control which VRFs import or export routes, not unique customer identifiers; overlapping customer address space is separated by distinct route distinguishers prepended to prefixes. RTs are tempting because they do govern VPN route distribution, and would be the answer if the question asked how the provider controls route import and export between VRFs.
Visual reference
Quick reference
Routing Protocol Comparison
| Protocol | Metric | Max Hops | Algorithm | Type |
|---|---|---|---|---|
| RIP v2 | Hop count | 15 | Bellman-Ford | Distance vector |
| OSPF | Cost (bandwidth) | Unlimited | Dijkstra (SPF) | Link state |
| EIGRP | Composite metric | Unlimited | DUAL | Hybrid |
| IS-IS | Cost | Unlimited | Dijkstra | Link state |
| BGP | Policy / attributes | Unlimited | Path vector | Path vector |
RIP's 15-hop limit makes it unsuitable for large networks. OSPF and EIGRP dominate modern enterprise deployments.
Go deeper
Related to this question
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on 350-401
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which three statements about MPLS Layer 3 VPNs are true? (Choose three.)
hard- ✓ A.MP-BGP is used to exchange VPNv4 routes between PE routers.
- ✓ B.Each customer site requires a separate VRF on the PE router.
- C.The P router maintains a full routing table for all VPN customers.
- D.A single MPLS label is used for both transport and VPN identification.
- ✓ E.The PE router performs the routing between the CE device and the MPLS core.
Why A: Option A is correct because MPLS L3VPN PEs use MP-BGP (multiprotocol BGP, specifically the VPNv4 address family) to exchange customer VPN routes with the appropriate route targets and labels. Option B is correct because each customer site is mapped to a separate VRF on the PE, which provides logical routing and forwarding isolation per VPN. Option E is correct because the PE router is the edge device that peers with the CE and performs the routing between the CE and the MPLS core, including VRF route leaking and label imposition. Option C is not correct because P routers only forward labeled packets and do not maintain per-VPN customer routing tables. Option D is not correct because MPLS L3VPN typically uses a two-label stack: an outer transport label for the LSP and an inner VPN label for the VRF/route identification.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.