Courseiva
mediumMultiple Choice

350-401 Practice Question: Examine the following VRF configuration: vrf…

Examine the following VRF configuration:

vrf definition BLUE rd 1:1 route-target export 1:1 route-target import 2:2 !

interface GigabitEthernet0/5

vrf forwarding BLUE

ip address 10.0.0.1 255.255.255.0

What is the effect of having different export and import route targets?

⚠ Common exam trap

Cisco often tests the misconception that export and import route targets must match, but in reality they can differ to control route propagation in complex MPLS VPN designs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The VRF exports routes tagged with RT 1:1 and imports routes tagged with RT 2:2, enabling selective route exchange.

The VRF BLUE configuration uses different route targets for export (1:1) and import (2:2). This enables selective route exchange: routes learned in VRF BLUE are exported with RT 1:1, and only routes tagged with RT 2:2 are imported into VRF BLUE. This is a common design for hub-and-spoke or inter-VRF route leaking scenarios where import and export RTs are intentionally asymmetric.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The VRF exports routes tagged with RT 1:1 and imports routes tagged with RT 2:2, enabling selective route exchange.

    Why this is correct

    This is correct because in a VRF, the route-target export (RT 1:1) is attached as a BGP extended community to all routes the VRF advertises, while the route-target import (RT 2:2) filters incoming routes based on whether they carry RT 2:2. Since the export and import RTs are independent, this asymmetric configuration allows the VRF to selectively exchange routes with other VRFs or VRF instances in a hub-and-spoke or inter-VRF routing design, without needing the RTs to match.

  • ✗

    The configuration is invalid because export and import RTs must be identical.

    Why it's wrong here

    This is incorrect because export and import route targets are configured as separate commands under the VRF — 'route-target export' and 'route-target import' — and they are intentionally allowed to differ. Cisco IOS and IOS-XE do not require them to be identical; in fact, asymmetric RTs are a common technique to create directional route exchange, such as allowing a hub to import spokes' routes while spokes only import the hub's routes, or to control route distribution in MPLS L3VPN inter-AS scenarios.

  • ✗

    The VRF will only import routes from other VRFs that also have RT 1:1.

    Why it's wrong here

    This is incorrect because it reverses the role of the route targets. The VRF's import RT is 2:2, meaning it accepts and installs routes that carry the RT 2:2 extended community, regardless of which VRF or PE router exported them. A route carrying RT 1:1 would be ignored by this VRF's import process, since the import filter matches only RT 2:2, so the claim that it imports routes with RT 1:1 is the opposite of what actually happens.

  • ✗

    This configuration disables route advertisement for VRF BLUE.

    Why it's wrong here

    This is incorrect because configuring an export route-target does not disable route advertisement; it enables it by tagging the VRF's routes with the specified RT. In this scenario, VRF BLUE's routes are exported with RT 1:1, allowing them to be advertised to other VRFs or VRF instances that import RT 1:1. Disabling advertisement would require a different configuration, such as removing the export RT, applying a route-map that denies redistribution, or using 'no export' in BGP—none of which are implied by the given configuration.

Quick reference

Asymmetric Encryption Algorithm Comparison

AlgorithmKey ExchangeSignaturesEquivalent Security KeyNotes
RSA-3072YesYes128-bitWidely deployed; slow for bulk data
ECDSA P-256NoYes128-bitFast signatures; standard TLS certs
ECDH / ECDHEYesNo128-bitPerfect forward secrecy in TLS 1.3
DH / DHEYesNo128-bit (3072-bit key)Replaced by ECDHE in modern TLS
Ed25519NoYes~128-bitSSH keys, modern PKI

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.