300-410 Infrastructure Security Practice Question
A network engineer is configuring Unicast Reverse Path Forwarding (uRPF) on a Cisco IOS router to mitigate IP spoofing. The router has two interfaces: GigabitEthernet0/0 connecting to the internet (untrusted) and GigabitEthernet0/1 connecting to the internal network (trusted). The engineer wants to enable strict uRPF on the untrusted interface. Which command should be applied to GigabitEthernet0/0?
⚠ Common exam trap
Many exam-takers confuse strict and loose uRPF modes, or using the deprecated command syntax, which may not be supported or may behave differently.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ip verify unicast source reachable-via rx
Strict uRPF is enabled with the command ip verify unicast source reachable-via rx on the interface. It ensures that the source IP address of incoming packets is reachable via the same interface, effectively dropping packets with spoofed source addresses that would not be routed back out that interface.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
ip verify unicast source reachable-via any
Why it's wrong here
The command ip verify unicast source reachable-via any enables loose uRPF, which only checks that the source IP is reachable via any interface in the routing table, not necessarily the receiving interface. This is less strict and does not prevent spoofing as effectively as strict mode, especially on an untrusted interface where strict uRPF is desired.
- ✓
ip verify unicast source reachable-via rx
Why this is correct
The command ip verify unicast source reachable-via rx enables strict uRPF, which checks that the source IP address of incoming packets is reachable via the same interface the packet was received on. This is the correct configuration for the untrusted interface to prevent spoofed source addresses.
- ✗
ip verify unicast reverse-path
Why it's wrong here
The command ip verify unicast reverse-path is the older syntax for strict uRPF, but it is deprecated in favor of the reachable-via rx syntax. While it might still work on some platforms, the current recommended command is ip verify unicast source reachable-via rx. Using the deprecated command could lead to inconsistent behavior or lack of support in newer IOS versions.
- ✗
ip verify unicast source reachable-via rx allow-default
Why it's wrong here
The allow-default keyword allows the default route to be used for the reachability check. This weakens strict uRPF because packets with source addresses that are only reachable via the default route would be permitted, which could allow spoofed traffic. On an untrusted interface, strict uRPF without allow-default is preferred to ensure the source is reachable via a specific route on the receiving interface.
Go deeper
Related to this question
About these practice questions
One of 1,401 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.