Cisco 300-515 SPVI Service Provider VPN Practice Exam
Cover all four SPVI v1.1 domains — VPN Architecture, Layer 2 VPNs, Layer 3 VPNs, and IPv6 VPNs — with objective-mapped questions, immediate feedback in Learn mode, and a full timed simulation in Exam mode.
Start 24-hour free trial →300-515 SPVI exam at a glance
- Vendor
- Cisco
- Exam code
- 300-515
- Exam name
- Implementing Cisco Service Provider VPN Services (SPVI)
- Blueprint
- Cisco exam topics v1.1 — four domains weighted 25 / 30 / 35 / 10
- Certification earned
- Cisco Certified Specialist – Service Provider VPN Services Implementation
- Counts toward
- CCNP Service Provider (satisfies the concentration-exam requirement alongside the 350-501 SPCOR core)
- Duration
- 90 minutes
- Question count
- Cisco does not publish a fixed item count for this exam
- Passing score
- Cisco does not publish a fixed passing score; cut scores are set by psychometric analysis and are not disclosed
- Prerequisites
- None formally required. Cisco recommends practical service-provider experience with MPLS, BGP, and IOS XR / IOS XE VPN configuration.
- Cost (USD)
- $300 USD, or redeem Cisco Learning Credits (regional pricing varies)
- Delivery
- Pearson VUE test center or online proctored; scheduled through the Cisco certification portal
- Languages
- English
- Validity
- 3 years (CCNP-level); recertify by exam or by earning 80 Continuing Education credits
Sources: Cisco — 300-515 SPVI exam page · Cisco — SPVI v1.1 exam topics (PDF). Verify current details with Cisco before scheduling.
About the Cisco 300-515 SPVI certification
SPVI is one of the four concentration exams under CCNP Service Provider. Pass it and you earn the standalone Cisco Certified Specialist – Service Provider VPN Services Implementation credential; pair it with the 350-501 SPCOR core exam and you complete the full CCNP Service Provider certification. It is deliberately narrow and deep: the entire 90 minutes is spent on carrier VPN service delivery, not on general routing or enterprise security.
The single most common preparation mistake is treating SPVI as an enterprise VPN exam. It is not. There is no IPsec, no SSL VPN, no remote-access client, and no firewall content — that material belongs to 300-730 SVPN on the security track. SPVI is about MPLS-based provider VPNs: VRFs, route distinguishers and route targets, MP-BGP VPNv4 and VPNv6 signalling, EVPN and pseudowire services, and the Inter-AS options that stitch VPNs across autonomous system boundaries. Roughly two-thirds of the blueprint verbs are troubleshoot and implement rather than describe, so recall alone will not carry you — you need to reason about control-plane and data-plane behaviour under failure.
Every PowerKram question maps to one of the four v1.1 domains and cites the Cisco document it was derived from, so a weak score becomes a specific reading list instead of a vague instruction to study more. For the broader context on how vendor certification tracks fit together, see our guide to how IT certification tracks are structured.
300-515 SPVI exam domains and weights
Cisco publishes four weighted domains in the v1.1 exam topics document. The weights sum to 100%. Layer 3 VPNs is the heaviest single area, and together with Layer 2 VPNs it accounts for roughly two-thirds of the exam — plan study time accordingly.
MP-BGP and PE-CE routing requirements; troubleshooting Intra-AS L3VPNs across PE-CE, PE-PE, and PE-RR; multicast VPN (intranet, extranet, MLDP); extranet and shared services via route-target import/export and route policy; Inter-AS options A, B, AB, and C; Carrier Supporting Carrier concepts.
Troubleshooting E-LAN, E-Line, and E-Tree services; EVPN concepts covering data-plane and control-plane operation, multihoming, suppression, traffic forwarding, and traffic engineering with RSVP-TE and SR-TE over IS-IS and OSPF; Ethernet OAM; implementing EVPN IRB, EVPN VPWS, and EVPN native.
Comparing Layer 2 versus Layer 3 VPN and Inter-AS versus Intra-AS designs; troubleshooting the underlay core IGP and LSP; Layer 2 service architecture using IOS XR Ethernet Flowpoints and IOS XE Ethernet Virtual Circuits; L3VPN control plane (MP-BGP, RD, VPNv4, RT, VPN label, VRF, additional paths, PIC, unified BGP/MPLS) and data plane (underlay label, VRF forwarding, VPNv6).
IPv6 VPN routing requirements including MP-BGP 6VPE and 6PE and the PE-CE routing protocol; troubleshooting the IPv6 VPN provider edge across PE-PE and PE-CE.
Source: Cisco — Implementing Cisco Service Provider VPN Services v1.1 (300-515) exam topics. Cisco notes that other related topics may appear on any specific delivery of the exam.
Who the 300-515 SPVI exam is for
SPVI is written for engineers who already operate carrier or large-scale MPLS networks. Cisco sets no formal prerequisite, but the blueprint assumes you can already read a BGP table, interpret a label stack, and work comfortably in IOS XR as well as IOS XE.
- Service provider network engineers who provision and troubleshoot L2VPN and L3VPN services for enterprise customers on a shared backbone.
- MPLS and backbone specialists moving from pure transport work into VPN service delivery, where RD/RT design and route leaking become daily concerns.
- Network architects designing Inter-AS interconnects, Carrier Supporting Carrier arrangements, or EVPN migrations away from legacy VPLS.
- CCNP Service Provider candidates choosing a concentration after the 350-501 SPCOR core — SPVI is the natural pick if your day job is customer VPN services rather than advanced routing (300-510 SPRI) or cloud network infrastructure (300-540 SPCNI).
If you are still building core networking foundations, CCNA 200-301 is the right starting point — SPVI assumes that material as a given. To see where a service-provider VPN specialisation leads in terms of roles, responsibilities, and progression, review the network engineering career paths this certification supports.
What this 300-515 SPVI practice exam delivers
Learn mode
Get the correct answer, why each distractor fails, and a direct link to the Cisco document behind it — immediately after each question. Most valuable in the Layer 3 VPN domain, where Inter-AS options and route-target behaviour are easy to half-remember.
Exam mode
A full 90-minute timed simulation matching the real SPVI sitting, so you build pacing on troubleshooting scenarios that reward reading the topology before the options.
Source-linked explanations
Every answer cites the Cisco configuration guide or support document it derives from — IOS XR L2VPN and L3VPN guides, MPLS OAM, and the SPVI exam topics — so you can verify rather than memorise.
Score by SPVI domain
Results break down across the four real blueprint domains — VPN Architecture, Layer 2 VPNs, Layer 3 VPNs, and IPv6 VPNs — so you know whether to revisit EVPN multihoming or 6VPE before your next attempt.
Sample 300-515 SPVI practice questions
Ten free questions spread across the four current SPVI domains, each with a full explanation and a source link to the Cisco documentation it was built from. The complete bank is available with the 24-hour trial.
In an MPLS L3VPN, two customers both use the 10.1.0.0/16 address space. Which control-plane construct makes their otherwise identical prefixes unique as they are carried across the provider backbone in MP-BGP?
- The route target attached as an extended community
- The route distinguisher prepended to the IPv4 prefix
- The VPN label allocated by the egress PE
- The VRF name configured on each PE
Show answer & explanation
Correct: B — the route distinguisher. The RD is prepended to the customer IPv4 prefix to form a globally unique 96-bit VPNv4 address, which is what allows two customers with overlapping address space to be advertised independently through MP-BGP.
Why not the others: The route target (A) controls which VRFs import and export a route — it governs VPN membership, not uniqueness. The VPN label (C) is a forwarding-plane construct that tells the egress PE which VRF to use; it does not disambiguate the advertisement itself. The VRF name (D) is locally significant to one router and is never carried in BGP.
Source: Cisco — MPLS VPN basic configuration and RD/RT operation → Further reading: PowerKram — How IT certification tracks are structured →A customer VPN is down between two sites. The PE routers hold the correct VPNv4 routes and the VRFs are populated, but traffic is black-holed in the core. Which underlay element should be validated first?
- The route-target import and export policy on each PE
- The route distinguisher configured under the VRF
- The PE-CE routing protocol adjacency
- The end-to-end label switched path between the ingress and egress PE
Show answer & explanation
Correct: D — the label switched path. When the control plane is healthy but forwarding fails, the fault is in the underlay transport. MPLS LSP ping and traceroute send MPLS echo request and reply messages down the label stack to validate the LSP and isolate the failing hop.
Why not the others: RT policy (A) and the route distinguisher (B) are control-plane constructs, and the question already states routes are present and VRFs populated. The PE-CE adjacency (C) governs the customer edge, not the provider core where the traffic is being dropped.
Source: Cisco — Implementing MPLS OAM (LSP ping and traceroute) →A provider is replacing legacy VPLS with EVPN. Which characteristic of EVPN most directly addresses the VPLS limitation the provider is trying to escape?
- MAC learning is moved into the control plane and distributed by MP-BGP
- Customer MAC addresses are no longer learned anywhere in the network
- The core no longer requires an IGP or label distribution
- Broadcast traffic is eliminated from the bridge domain
Show answer & explanation
Correct: A — control-plane MAC learning via MP-BGP. EVPN replaces the data-plane flood-and-learn behaviour of VPLS with control-plane MAC learning, which is what enables all-active multihoming with per-flow load balancing.
Why not the others: MAC addresses are still learned (B) — the change is where and how. The core still needs an IGP and label distribution (C); EVPN is a service overlay, not a replacement for the underlay. Broadcast and BUM traffic still exist (D), which is precisely why EVPN defines designated forwarder election and split-horizon filtering.
Source: Cisco — EVPN features and control-plane MAC learning → Further reading: PowerKram — Enterprise security practices →A customer site is multihomed to two PEs in an EVPN deployment. Which identifier must be configured identically on both PEs so the set of links is recognised as one Ethernet segment?
- The EVPN instance value
- The Ethernet Segment Identifier
- The bridge domain name
- The route distinguisher
Show answer & explanation
Correct: B — the Ethernet Segment Identifier. An Ethernet segment is the set of links connecting a multihomed device, and it is assigned a unique non-zero ESI that must match on the peering PEs so they recognise the shared segment and can elect a designated forwarder.
Why not the others: The EVI (A) identifies the EVPN instance, not the segment, and multiple segments can exist within one EVI. The bridge domain name (C) is locally significant. The route distinguisher (D) makes advertisements unique per PE and should generally differ, not match.
Source: Cisco — EVPN Ethernet segment and ESI concepts →An operator needs proactive, per-VLAN connectivity monitoring and fault isolation across an end-to-end Ethernet service that traverses multiple provider devices. Which mechanism is designed for this?
- Ethernet Connectivity Fault Management
- Bidirectional Forwarding Detection on the core links
- Link Layer Discovery Protocol
- Spanning Tree Protocol topology change notifications
Show answer & explanation
Correct: A — Ethernet CFM. CFM is a service-level OAM protocol providing proactive connectivity monitoring, fault verification, and fault isolation per VLAN, and its frames traverse the entire end-to-end Ethernet network rather than a single link.
Why not the others: BFD (B) gives fast failure detection but is a per-link or per-session mechanism without service-level fault isolation. LLDP (C) is a neighbour discovery protocol confined to a single link. STP notifications (D) signal topology changes for loop prevention and are not a monitoring or fault-isolation tool.
Source: Cisco — Configuring Ethernet OAM and CFM →Two providers must interconnect an L3VPN across an autonomous system boundary. In the Inter-AS option where the ASBRs exchange VPNv4 routes and VPN labels over an eBGP session without holding customer VRFs, which option is in use?
- Option A
- Option B
- Option C
- Carrier Supporting Carrier
Show answer & explanation
Correct: B — Inter-AS Option B. In Option B the ASBRs peer using eBGP and exchange VPNv4 routes together with VPN labels; the ASBR does not hold customer VRFs but carries the VPNv4 routes that must cross to the other autonomous system, kept unique by route distinguisher and filtered by route target.
Why not the others: Option A (A) uses back-to-back VRF connectivity with a subinterface and BGP session per VPN, so the ASBRs do hold VRFs and the traffic between them is IP rather than labelled. Option C (C) pushes VPNv4 exchange to the route reflectors or PEs with the ASBRs carrying only labelled IPv4 loopbacks. CSC (D) is a different architecture where one carrier provides transport to another carrier.
Source: Cisco — MPLS VPN Inter-AS options → Further reading: PowerKram — Network engineer role and career path →A provider hosts a shared DNS service that several customer VRFs must reach, while those customers must remain unable to reach one another. Which mechanism achieves this?
- Assigning every customer the same route distinguisher
- Placing all customers into a single VRF with access lists
- Selective route-target import and export between the shared-services VRF and each customer VRF
- Disabling MP-BGP and using static routes to the shared service
Show answer & explanation
Correct: C — selective route-target import and export. Extranet and shared-services designs work by controlling which route targets each VRF imports and exports, optionally refined with route policy, so the shared prefixes leak into every customer VRF while customer prefixes never leak between customers.
Why not the others: A shared RD (A) does not create reachability and would defeat the uniqueness the RD exists to provide. A single VRF with ACLs (B) collapses the isolation that VRFs supply and does not scale. Static routes without MP-BGP (D) abandons the VPN control plane entirely and still would not enforce customer-to-customer isolation.
Source: Cisco — MPLS VPN route-target import and export →A customer needs multicast carried between VPN sites across the provider backbone using label switched paths, so the core does not have to run PIM. Which mVPN approach fits?
- Rosen GRE with a default multicast distribution tree
- Unicast replication from the ingress PE to every egress PE
- Extending the customer PIM domain into the provider core
- An MLDP-based profile building label switched multicast trees
Show answer & explanation
Correct: D — an MLDP-based profile. With MLDP, customer multicast packets are encapsulated in MPLS labels and forwarded over label switched paths in the same manner as unicast, which removes the requirement for PIM in the provider core.
Why not the others: Rosen GRE (A) encapsulates customer multicast into provider multicast packets and specifically requires PIM enabled in the core — the opposite of the stated requirement. Unicast replication (B) does not scale and is not an mVPN profile. Extending the customer PIM domain into the core (C) breaks the separation that mVPN exists to preserve.
Source: Cisco — Multicast VPN, Rosen GRE and MLDP profiles →A provider must deliver IPv6 VPN services to customers while keeping the existing MPLS IPv4 core unchanged. Which approach does 6VPE use to make this work?
- Dual-stacking every P router in the core so it forwards native IPv6
- Translating customer IPv6 into IPv4 at the ingress PE
- Carrying IPv6 VPN reachability in MP-BGP and forwarding over the existing IPv4 MPLS LSPs
- Building GRE tunnels between customer edge routers
Show answer & explanation
Correct: C — MP-BGP reachability over the existing IPv4 MPLS LSPs. 6PE and 6VPE reuse the existing MPLS IPv4 core for IPv6 transport, relying on multiprotocol BGP extensions on the dual-stacked PE routers to exchange IPv6 reachability together with an MPLS label for each prefix.
Why not the others: Dual-stacking every P router (A) is exactly the disruptive core upgrade 6VPE is designed to avoid — only the edge routers are dual-stacked. Protocol translation (B) is not part of the 6VPE model. CE-to-CE GRE tunnels (D) would bypass the provider VPN service altogether.
Source: Cisco — Implementing IPv6 VPN Provider Edge transport over MPLS → Further reading: PowerKram — Cloud engineer role and career path →A service must provide both bridged Layer 2 connectivity within a subnet and routed forwarding between subnets on the same EVPN PE. Which EVPN capability provides this?
- EVPN VPWS
- EVPN E-Tree
- EVPN IRB
- EVPN native with split-horizon filtering only
Show answer & explanation
Correct: C — EVPN IRB. Integrated routing and bridging combines Layer 2 bridging within a bridge domain and Layer 3 routing between bridge domains on the same PE, which is what the requirement for both intra-subnet and inter-subnet forwarding describes.
Why not the others: EVPN VPWS (A) delivers point-to-point pseudowire service with no routing function. E-Tree (B) enforces a root-and-leaf forwarding restriction and is about traffic policy rather than routing between subnets. EVPN native with split-horizon filtering (D) addresses loop and duplicate prevention on multihomed segments, not inter-subnet routing.
Source: Cisco — Configure EVPN IRB →Keep going: Learning & Career resources
A VPN services specialisation compounds when you understand both the wider certification landscape and where the skill set leads. Two PowerKram hubs back this exam.
Deep dive: SPVI format, scoring, study path, and how it fits CCNP Service Provider
Exam format and how it is scored
SPVI is a 90-minute exam delivered in English through Pearson VUE, either at a test centre or online with a proctor. Cisco does not publish a fixed item count or a fixed passing score for this exam; cut scores are established through psychometric analysis and are deliberately not disclosed, so any specific pass percentage you see quoted on a third-party site is an assumption rather than a published fact. Expect a mixture of multiple choice, multiple response, and drag-and-drop items, with a strong bias toward scenario-based troubleshooting given how many blueprint sub-topics begin with the verb troubleshoot. See how certification exams are structured →
How SPVI fits the CCNP Service Provider track
CCNP Service Provider requires two exams: the 350-501 SPCOR core plus one concentration. SPVI is one of four concentration choices alongside 300-510 SPRI (advanced routing), 300-535 SPAUTO (automation), and 300-540 SPCNI (cloud network infrastructure). Passing SPVI on its own still earns the standalone Cisco Certified Specialist – Service Provider VPN Services Implementation credential, which is worth knowing if you want a certification milestone before committing to the full core exam. Compare the SPRI concentration →
Where candidates lose marks
Three patterns recur. First, confusing SPVI with the enterprise security VPN exam and studying IPsec and SSL VPN material that is not on this blueprint at all. Second, memorising the Inter-AS options as labels without understanding what the ASBR actually holds and exchanges in each — questions are written to reward that distinction. Third, treating EVPN as a naming change over VPLS rather than a control-plane redesign, which makes multihoming, designated forwarder election, and split-horizon questions unnecessarily hard. The Layer 2 and Layer 3 domains together are roughly two-thirds of the exam, so weakness in either is expensive.
Realistic study path
Most candidates with hands-on provider experience need six to ten weeks. A workable sequence: read the v1.1 exam topics document and map each sub-topic to something you have actually configured; close the gaps with the Cisco IOS XR L2VPN and L3VPN configuration guides rather than summary blogs; build lab topologies for the Inter-AS options and for EVPN multihoming, since both are far clearer once you have watched the routes and labels move; then run timed Exam-mode sittings to expose which of the four domains is lagging. Cisco also publishes a guided learning path for this exam. Cisco SPVI exam page and training options →
Cost, scheduling, and recertification
The exam is $300 USD, or you can redeem Cisco Learning Credits; regional pricing varies. Scheduling runs through the Cisco certification portal into Pearson VUE. CCNP-level certifications are valid for three years, and Cisco offers several recertification routes: pass one technology core exam, pass any two professional concentration exams, pass a CCIE lab, or earn 80 Continuing Education credits. The requirement must be satisfied before the expiry date — letting a certification lapse means repeating the full process. Cisco CCNP Service Provider certification page →
Career outlook for SPVI-credentialed engineers
SPVI is a specialist credential and it signals something specific: that you can deliver and troubleshoot customer VPN services on a carrier backbone. That maps to roles at telecoms operators, large managed service providers, internet exchanges, and the network teams of organisations big enough to run their own MPLS core. It pairs naturally with advanced routing skills for a broader service provider profile, and with automation skills as providers move provisioning toward templated, API-driven workflows. Network engineering career paths →
Frequently asked questions about the 300-515 SPVI exam
What are the 300-515 SPVI exam domains and their weights?
What is the passing score for the 300-515 SPVI exam?
Does 300-515 SPVI cover IPsec and remote-access VPNs?
Are there prerequisites for the 300-515 SPVI exam?
How much does 300-515 SPVI cost and how long is it?
What certification do I earn by passing 300-515 SPVI?
Start your free 24-hour 300-515 SPVI practice trial
Full access to the question bank, both study modes, source-linked explanations, and score-by-domain reporting. No credit card required.
Start free trial →