mediumMultiple Select
350-401 Practice Question: Which two statements about MPLS Layer 3 VPNs are…
Which two statements about MPLS Layer 3 VPNs are true? (Choose two.)
⚠ Common exam trap
It's easy for candidates to confuse the roles of P and PE routers — candidates often assume every router in the MPLS domain must know customer routes, when in fact P routers only swap the outer transport label and remain VRF-unaware.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
PE routers use MP-BGP to exchange VPNv4 routes that include the route distinguisher and the VPN label.
Option A is correct because in an MPLS Layer 3 VPN, PE routers use MP-BGP (multiprotocol BGP, specifically the VPNv4 address family) to exchange customer routes, and each VPNv4 NLRI carries the 8-byte route distinguisher that makes the prefix unique plus the VPN label (an inner MPLS label) used by the egress PE to identify the customer VRF. Option D is correct because each VRF on a PE router is a separate routing and forwarding instance with its own RIB and FIB, which is what keeps overlapping customer address space isolated and allows per-VRF label assignment. Option B is wrong because P routers in the core only need to forward labeled packets based on the outer transport label; they do not hold per-customer VRF tables (that is the whole point of the MPLS L3VPN architecture). Option C is wrong because CE routers are typically ordinary IP routers that do not run MPLS or participate in label distribution; they simply peer with the PE via a routing protocol or static routes. Option E is wrong because the MPLS label stack in an L3VPN normally contains at least two labels: an outer IGP/LDP transport label used to reach the egress PE and an inner VPN label used to identify the customer VRF, and it can contain more labels in some scenarios.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
PE routers use MP-BGP to exchange VPNv4 routes that include the route distinguisher and the VPN label.
Why this is correct
MP-BGP carries VPNv4 routes between PE routers, with each route tagged by a route distinguisher for uniqueness and a VPN label for forwarding. This exchange populates VRFs across the provider core, satisfying the stem's requirement for a true MPLS Layer 3 VPN statement.
- ✗
P routers in the MPLS core must maintain a full routing table for each customer VRF.
Why it's wrong here
Provider (P) routers forward labelled packets using only the IGP and LDP-derived label information; they hold no customer VRF tables, since VRFs live on PE routers. The option is tempting because PE routers do maintain per-VRF routing tables, and that PE behaviour is easy to misattribute to the core.
- ✗
CE routers must run MPLS and participate in the label distribution with the PE router.
Why it's wrong here
CE routers sit outside the provider's MPLS domain and exchange plain IP routing with the PE; they do not run MPLS or participate in label distribution. It is tempting because MPLS forwarding occurs within the VPN, but label distribution happens only between PE routers.
- ✓
Each VRF on a PE router maintains a separate routing table and forwarding table per customer.
Why this is correct
VRFs provide logical routing and forwarding isolation on each PE router, so overlapping customer address space stays separate. Each VRF holds its own routing and forwarding table per customer, satisfying the stem's requirement for a true statement about MPLS Layer 3 VPN separation.
- ✗
The MPLS label stack in a Layer 3 VPN always contains exactly one label.
Why it's wrong here
A Layer 3 VPN label stack normally carries two labels: an outer IGP/LDP transport label and an inner VPN label identifying the customer VRF. Single-label stacks occur in plain MPLS forwarding or PHP scenarios, which is why the claim can appear credible when only the transport label is considered.
Quick reference
Routing Protocol Comparison
| Protocol | Metric | Max Hops | Algorithm | Type |
|---|---|---|---|---|
| RIP v2 | Hop count | 15 | Bellman-Ford | Distance vector |
| OSPF | Cost (bandwidth) | Unlimited | Dijkstra (SPF) | Link state |
| EIGRP | Composite metric | Unlimited | DUAL | Hybrid |
| IS-IS | Cost | Unlimited | Dijkstra | Link state |
| BGP | Policy / attributes | Unlimited | Path vector | Path vector |
RIP's 15-hop limit makes it unsuitable for large networks. OSPF and EIGRP dominate modern enterprise deployments.
Go deeper
Related to this question
Learn chapter
VLANs and Spanning Tree Protocol Concepts
Key term
Virtual Routing and Forwarding
Virtual Routing and Forwarding (VRF) is a technology that allows a single physical router to operate like multiple independent routers by keeping separate routing tables and forwarding decisions for each instance.
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.