300-410 Infrastructure Security Practice Question
A network engineer is configuring a Cisco IOS XE router to mitigate spoofed source addresses on a WAN-facing interface using Unicast Reverse Path Forwarding. The WAN provider uses asymmetric routing, where return traffic from the provider occasionally arrives on a different interface than the one used for outbound traffic. The engineer wants to avoid dropping legitimate packets while still providing anti-spoofing protection. Which uRPF mode should the engineer configure on the WAN interface?
⚠ Common exam trap
The trap here is assuming that strict mode is always the best anti-spoofing choice, when asymmetric routing requires loose mode to avoid dropping legitimate traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Loose mode
Loose mode verifies that the source address exists in the routing table without requiring the packet to arrive on the same interface as the reverse route. This allows asymmetric traffic to pass while still dropping packets with completely unknown source addresses, providing useful anti-spoofing protection. Strict and feasible path modes would drop legitimate asymmetric traffic, and VRF-aware mode does not change the fundamental same-interface requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Loose mode
Why this is correct
Loose mode checks only that the source address is reachable via any route in the routing table, not necessarily the receiving interface. This preserves anti-spoofing protection for addresses that are completely unknown while allowing legitimate traffic that arrives over a different path than the outbound route. It is the appropriate choice when asymmetric routing exists on the WAN link.
- ✗
Strict mode
Why it's wrong here
Strict mode requires that the source address be reachable via the same interface on which the packet was received. In an asymmetric routing environment, return traffic arriving on a different interface would not match the reverse path entry, causing legitimate packets to be dropped. Strict mode is therefore not suitable when paths are asymmetric, despite offering the strongest anti-spoofing enforcement.
- ✗
VRF-aware strict mode
Why it's wrong here
VRF-aware uRPF applies the reverse lookup within the VRF associated with the receiving interface. While useful in MPLS or VRF-lite environments, it does not relax the same-interface requirement, so asymmetric routing would still cause legitimate packets to be dropped. It is not the correct mitigation for the described WAN scenario.
- ✗
Feasible path mode
Why it's wrong here
Feasible path mode is an extension of strict mode that uses the RIB-FIB consistency check plus a feasible path check derived from BGP. It still requires the packet to arrive on an interface that matches the reverse path, so it does not solve the asymmetric routing problem and could still drop legitimate traffic. It is intended for environments using BGP with additional path verification.
Quick reference
Asymmetric Encryption Algorithm Comparison
| Algorithm | Key Exchange | Signatures | Equivalent Security Key | Notes |
|---|---|---|---|---|
| RSA-3072 | Yes | Yes | 128-bit | Widely deployed; slow for bulk data |
| ECDSA P-256 | No | Yes | 128-bit | Fast signatures; standard TLS certs |
| ECDH / ECDHE | Yes | No | 128-bit | Perfect forward secrecy in TLS 1.3 |
| DH / DHE | Yes | No | 128-bit (3072-bit key) | Replaced by ECDHE in modern TLS |
| Ed25519 | No | Yes | ~128-bit | SSH keys, modern PKI |
Go deeper
Related to this question
Learn chapter
ACL-Based Traffic Filtering and Policy-Based Routing
Key term
MPLS Layer 3 VPN
A technology that uses Multiprotocol Label Switching to create secure, scalable virtual private networks that connect multiple sites at the network layer, where the service provider manages routing between customer sites.
Key term
uRPF
Unicast Reverse Path Forwarding is a network security feature that verifies the source address of incoming packets to prevent IP spoofing attacks.
About these practice questions
Courseiva writes every 300-410 question from scratch — 1,401 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.