easyMultiple Choice
350-401 Practice Question: A company uses VRF-lite to separate management…
A company uses VRF-lite to separate management traffic (VRF MGMT) from user traffic (VRF USER) on a Cisco Catalyst 3850 stack. The management network is 10.0.0.0/24, and the user network is 192.168.1.0/24. The engineer wants to allow SSH access from the user network to the management network for device administration. The switch has an SVI for each VRF. What is the simplest way to achieve this while maintaining VRF isolation?
⚠ Common exam trap
Cisco often tests the misconception that VRFs are completely isolated and cannot communicate without breaking isolation, but route leaking is the correct method to allow selective inter-VRF traffic while maintaining VRF separation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure a static route in VRF USER pointing to the VRF MGMT's SVI IP address, and enable route leaking between the VRFs.
VRF-lite inherently isolates routing tables, so to allow SSH from VRF USER to VRF MGMT while maintaining isolation, you must leak routes between the VRFs. A static route in VRF USER pointing to the VRF MGMT SVI IP address, combined with route leaking (e.g., using `route-map` and `import/export` commands), enables the necessary reachability without merging the VRFs. This is the simplest method as it avoids additional hardware or complex configurations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure a static route in VRF USER pointing to the VRF MGMT's SVI IP address, and enable route leaking between the VRFs.
Why this is correct
This is correct because VRF route leaking explicitly permits the USER VRF to learn a route to the management SVI in the MGMT VRF without merging the two routing tables. By configuring a static route in VRF USER with the MGMT SVI IP as the next hop, and then enabling route leaking (for example, via import/export route targets or an appropriate leak statement), the switch installs only the necessary prefix into USER's RIB. This allows SSH from USER hosts to reach the MGMT VRF while all other traffic remains isolated, preserving the path-isolation requirement with minimal configuration overhead.
- ✗
Place both SVIs in the same VRF and use access-lists to restrict traffic.
Why it's wrong here
This is incorrect because placing both SVIs in the same VRF destroys the VRF isolation that the requirement specifically asks to preserve. Even if you apply access-lists to restrict traffic, the USER and MGMT networks now share the same Layer 3 routing table and forwarding domain, so any ACL misconfiguration or missing entry could expose management resources. VRF separation is a control-plane and data-plane isolation mechanism; ACLs are stateless filters and cannot replicate the routing-table isolation that VRFs provide. This approach conflates security filtering with path isolation and fails the core requirement.
- ✗
Use a firewall between the VRFs to filter traffic.
Why it's wrong here
Introducing a firewall between the VRFs adds unnecessary hardware cost and configuration complexity, whereas the question explicitly asks for the simplest method to permit SSH while preserving isolation. A firewall is designed for stateful inspection and policy enforcement between security zones, making it the correct choice in a scenario requiring deep packet inspection or application-layer filtering, not for a basic inter-VRF route leak.
- ✗
Configure the switch to use the global routing table for SSH traffic only.
Why it's wrong here
This is incorrect because VRF assignment on a switch is an interface/VLAN-level property, not a per-protocol property. The switch cannot determine that SSH packets should use the global routing table while all other traffic from the same interface uses a VRF; the entire interface is bound to one VRF, and all traffic entering that interface is looked up in that VRF's RIB. Cisco IOS/IOS-XE does not provide a selective 'use global table for SSH only' feature, as the forwarding decision is made based on the ingress interface's VRF binding, not on the application protocol. Therefore this option is not operationally possible and would not solve the inter-VRF SSH requirement.
Go deeper
Related to this question
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.