Courseiva
mediumMultiple Choice

350-401 Practice Question: Using a dual-homed MPLS L3VPN connection with two…

A company is using a dual-homed MPLS L3VPN connection with two different ISPs. The CE router is running eBGP with both PE routers. The engineer wants to ensure that inbound traffic from the Internet to the company's web servers uses both links, but outbound traffic from the company should prefer ISP A. The company advertises the same /24 prefix to both ISPs. What BGP configuration should the engineer apply on the CE router?

⚠ Common exam trap

Cisco often tests the distinction between inbound and outbound traffic engineering: candidates confuse attributes that influence inbound traffic (like MED and AS path prepending) with those that influence outbound traffic (like local preference and weight), leading them to pick Option A or C incorrectly.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use AS path prepending on routes advertised to ISP B and set a higher local preference for routes learned from ISP A.

AS path prepending makes the route to ISP B appear less attractive for inbound traffic, while setting a higher local preference on routes learned from ISP A makes ISP A the preferred path for outbound traffic. This combination achieves the asymmetric routing goal: inbound traffic uses both links (since prepending only influences ISP B's decision, not ISP A's), and outbound traffic prefers ISP A due to the higher local preference.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Set a lower MED for routes advertised to ISP A and a higher MED for routes advertised to ISP B.

    Why it's wrong here

    Incorrect. MED is used to influence inbound traffic, but it is a multi-exit discriminator that is only considered when the same AS receives routes from multiple points. In a dual-homed scenario with different ISPs, MED is not typically used because the ISPs are different ASes.

  • ✓

    Use AS path prepending on routes advertised to ISP B and set a higher local preference for routes learned from ISP A.

    Why this is correct

    AS path prepending artificially extends the AS_PATH attribute, so ISP B sees a longer AS path and deprioritizes that route for inbound traffic, while the /24 remains advertised normally. Setting a higher local preference for routes learned from ISP A only influences routers inside your autonomous system, causing outbound traffic to prefer ISP A regardless of other attributes. This separation of inbound and outbound control is exactly the standard BGP traffic engineering approach.

  • ✗

    Advertise a more specific prefix (e.g., /25) to ISP A and a less specific prefix (/24) to ISP B.

    Why it's wrong here

    In BGP, a longer prefix (e.g., /25) is always preferred over a shorter one (e.g., /24) due to longest-prefix-match, so advertising a /25 only to ISP A would direct all traffic for that /25 range to ISP A, not split any portion to ISP B. ISPs commonly reject prefixes longer than /24 from customer announcements to keep the global routing table bounded, making this tactic impractical and unreliable. It can also lead to black-holing for the /25 if the ISP A link fails, since the /25 is not advertised to ISP B. Thus, this is a fragile, discouraged practice that does not achieve load balancing.

  • ✗

    Configure the CE router to use BGP multipath with both ISPs.

    Why it's wrong here

    BGP multipath installs multiple best paths into the RIB, letting the CE router load-balance outbound packets across both ISPs, but it does nothing to influence how remote ISPs choose to send inbound traffic. Inbound routing is controlled by BGP attributes advertised to the ISPs, such as AS path length and prefix length, which are not part of multipath decisions. Additionally, multipath requires the paths to have equal (or nearly equal) BGP best-path attributes (weight, local preference, AS path, MED, etc.), which is rarely true with two different ISPs without extensive route manipulation. For the intended scenario—different inbound and outbound behavior—multipath lacks the necessary inbound control.

Quick reference

Asymmetric Encryption Algorithm Comparison

AlgorithmKey ExchangeSignaturesEquivalent Security KeyNotes
RSA-3072YesYes128-bitWidely deployed; slow for bulk data
ECDSA P-256NoYes128-bitFast signatures; standard TLS certs
ECDH / ECDHEYesNo128-bitPerfect forward secrecy in TLS 1.3
DH / DHEYesNo128-bit (3072-bit key)Replaced by ECDHE in modern TLS
Ed25519NoYes~128-bitSSH keys, modern PKI

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.