mediumMultiple Choice
350-401 Practice Question: Consider the following configuration on a Cisco…
Consider the following configuration on a Cisco IOS-XE router:
vrf definition RED rd 100:1 route-target export 100:1 route-target import 100:1 !
interface GigabitEthernet0/2
vrf forwarding RED
ip address 10.10.10.1 255.255.255.0
Which statement is true about this configuration?
⚠ Common exam trap
Cisco often tests the misconception that the route-target must match the RD exactly, but in reality they serve different purposes and can be configured independently.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The VRF RED is correctly configured for MPLS L3VPN, and the interface is placed in VRF RED.
The configuration defines a VRF named RED with an RD of 100:1 and matching route-target import/export values, which is the standard setup for an MPLS L3VPN. The 'vrf forwarding RED' command under the interface assigns that interface to the VRF, isolating its routing table from the global table. This allows the router to participate in a Layer 3 VPN by importing and exporting routes with the specified route-target.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The VRF RED is correctly configured for MPLS L3VPN, and the interface is placed in VRF RED.
Why this is correct
This configuration is valid for MPLS L3VPN because the VRF RD (route distinguisher) uniquely identifies VRF RED in the MPLS domain, and the export/import route targets define how routes are distributed to other VRFs. Associating the interface with VRF RED via 'ip vrf forwarding RED' ensures that all traffic on that interface is forwarded using VRF RED's routing and CEF tables, not the global table. This is exactly how a customer edge interface is bound to a VPN routing instance in a service provider MPLS VPN deployment.
- ✗
The 'rd' command is optional for VRF operation and can be omitted.
Why it's wrong here
The RD is not optional for a VRF that will participate in MPLS L3VPN. Without a route distinguisher, the VRF routes cannot be made globally unique in the MP-BGP VPNv4 address family, because overlapping customer prefixes from different VRFs would collide. While a VRF without an RD can provide simple Layer 3 segmentation in a single device, it cannot export or import routes via MP-BGP for MPLS VPN services. Therefore, omitting 'rd' makes the VRF unsuitable for MPLS L3VPN operation.
- ✗
The 'route-target export' and 'route-target import' must match the RD value exactly.
Why it's wrong here
Route targets (RTs) and the route distinguisher (RD) serve distinct functions: the RD uniquely identifies the VRF in the MPLS backbone to keep routes separate, while RTs control which VRFs import and export routes to build VPN membership. RTs do not need to equal the RD; they are policy attributes attached to VPNv4 routes and can be arbitrarily chosen in the extended community format. In many designs they are set to the same value for simplicity, but matching is not a requirement for correct VRF operation.
- ✗
This configuration will cause the interface to use the global routing table for forwarding.
Why it's wrong here
An interface explicitly placed in VRF RED using the 'ip vrf forwarding RED' interface command will use VRF RED's routing and forwarding tables, not the global routing table. The global routing table is only used by interfaces that are not associated with any VRF, or after removing VRF membership. Committing this VRF assignment ensures that the interface's traffic is isolated and follows the VRF-specific routes, gateways, and VRF-aware features such as policy-based routing or multicast.
Go deeper
Related to this question
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.