300-410 Infrastructure Security Practice Question
A network administrator is configuring Unicast Reverse Path Forwarding (uRPF) on a Cisco IOS router to mitigate spoofed source IP addresses. The administrator wants to ensure that uRPF is applied in strict mode on an interface that connects to an ISP. Which command correctly enables strict uRPF on the interface?
⚠ Common exam trap
Many candidates confuse strict and loose uRPF modes: 'rx' enables strict mode, while 'any' enables loose mode.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ip verify unicast source reachable-via rx
Strict uRPF is enabled with the command 'ip verify unicast source reachable-via rx', which ensures the source address is reachable via the same interface the packet arrived on. This is the correct choice for an ISP-facing interface to prevent spoofed source addresses.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
ip verify unicast source reachable-via tx
Why it's wrong here
This command is used for uRPF in a different context, often for asymmetric routing scenarios where the source is reachable via a different interface. It does not enable strict mode and is not appropriate for the ISP-facing interface requirement.
- ✗
ip verify unicast reverse-path
Why it's wrong here
This is an older syntax for uRPF that may enable strict mode by default, but it is not the current recommended command. The modern explicit syntax is 'ip verify unicast source reachable-via rx'. This command may be deprecated or behave differently on some platforms.
- ✓
ip verify unicast source reachable-via rx
Why this is correct
This command enables strict uRPF, which checks that the source IP address is reachable via the same interface the packet was received on. It is the correct syntax for strict mode on Cisco IOS and is suitable for ISP-facing interfaces where symmetric routing is expected.
- ✗
ip verify unicast source reachable-via any
Why it's wrong here
This command enables loose uRPF, which only checks that the source is reachable via any interface, not necessarily the receiving interface. Loose mode is less strict and does not provide the same level of spoofing protection as strict mode, so it does not meet the requirement.
Go deeper
Related to this question
About these practice questions
One of 1,401 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.