Question 1,048 of 1,958
mediumMultiple ChoiceObjective-mapped
350-401 Practice Question: Is troubleshooting a VRF-lite deployment on a…
A network engineer is troubleshooting a VRF-lite deployment on a Cisco Nexus 9000 switch. Two VRFs, PROD and DEV, are configured. The switch has an SVI for VLAN 10 in VRF PROD and VLAN 20 in VRF DEV. A firewall is connected to a Layer 3 port in VRF PROD for internet access. The engineer needs to allow the DEV VRF to reach the internet through the same firewall, but without using a separate physical interface. What should the engineer configure?
⚠ Common exam trap
Cisco often tests the misconception that a single interface can belong to multiple VRFs simultaneously, or that VLANs can be shared across VRFs, leading candidates to choose options that violate VRF isolation principles.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure a static route in VRF DEV pointing to the firewall's IP address in VRF PROD, and use the route-map to leak the route.
VRF-lite does not support direct route leaking between VRFs without an external mechanism. By configuring a static route in VRF DEV pointing to the firewall's IP address (which resides in VRF PROD) and using a route-map to leak the route, the engineer enables inter-VRF routing. This allows DEV traffic to reach the firewall's interface in PROD without requiring a separate physical interface, as the route-map controls which prefixes are shared between VRFs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure a static route in VRF DEV pointing to the firewall's IP address in VRF PROD, and use the route-map to leak the route.
Why this is correct
Correct because route leaking allows one VRF to use a next-hop in another VRF. A static route with the appropriate VRF and route-map can achieve this.
- ✗
Place the firewall interface in both VRFs using the ip vrf forwarding command on the same interface.
Why it's wrong here
Incorrect because a single interface can only belong to one VRF.
- ✗
Create a VLAN trunk between the switch and firewall, and assign the same VLAN to both VRFs.
Why it's wrong here
Incorrect because a VLAN cannot be in two VRFs simultaneously.
- ✗
Use policy-based routing (PBR) in VRF DEV to forward traffic to the firewall's MAC address.
Why it's wrong here
Incorrect because PBR does not solve the VRF isolation; the firewall is in a different VRF, so the switch cannot directly forward to it without route leaking.
Visual reference
About these practice questions
Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →
Last reviewed: Jun 24, 2026
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.
Question Discussion
Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.
Sign in to join the discussion.