Courseiva
Infrastructure Security →mediumMultiple Choice

300-410 Infrastructure Security Practice Question

A network engineer is configuring Unicast Reverse Path Forwarding (uRPF) on a Cisco IOS router to mitigate spoofed source IP addresses. The engineer wants to ensure that packets are dropped if the source IP address is not reachable via the same interface they arrived on. The engineer configures 'ip verify unicast source reachable-via rx' on interface GigabitEthernet0/0. However, some legitimate traffic from a secondary path is being dropped. What is the most likely cause?

⚠ Common exam trap

Candidates often confuse strict and loose uRPF modes; 'rx' means strict, which is sensitive to asymmetric routing, while 'any' means loose.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The router uses strict uRPF, which requires the source to be reachable via the same interface; asymmetric routing causes legitimate packets to be dropped.

The 'reachable-via rx' option enables strict uRPF, which drops packets if the source IP is not reachable via the ingress interface. In networks with asymmetric routing, legitimate traffic may arrive on an interface that is not the best path back to the source, causing drops. Switching to loose uRPF ('reachable-via any') would alleviate this but reduce spoofing protection. CEF is typically enabled by default, so it is not the issue.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The interface must be configured with 'ip verify unicast source reachable-via any' to allow asymmetric routing.

    Why it's wrong here

    Configuring 'reachable-via any' would enable loose uRPF, which would allow the asymmetric traffic. However, this changes the security posture and is not the cause of the current drops. The question asks for the most likely cause of the drops, which is the strict mode itself, not a missing configuration.

  • ✗

    The uRPF feature requires CEF to be enabled, and CEF is not enabled on the router.

    Why it's wrong here

    uRPF relies on Cisco Express Forwarding (CEF) to perform the reverse path lookup. However, CEF is enabled by default on modern Cisco IOS routers. If CEF were disabled, uRPF would not function at all, but the scenario indicates some traffic is dropped, implying uRPF is active. Thus, CEF being disabled is unlikely.

  • ✗

    The router uses loose uRPF, which only checks if the source is reachable via any interface, so it should not drop legitimate traffic.

    Why it's wrong here

    Loose uRPF is configured with 'reachable-via any', not 'rx'. The 'rx' keyword specifically enables strict mode. Loose uRPF would not drop packets solely due to asymmetric routing, so this option misidentifies the mode and the cause.

  • ✓

    The router uses strict uRPF, which requires the source to be reachable via the same interface; asymmetric routing causes legitimate packets to be dropped.

    Why this is correct

    The 'reachable-via rx' option enables strict uRPF, which checks that the source IP is reachable via the same interface the packet arrived on. In asymmetric routing scenarios, where return traffic takes a different path, legitimate packets can be dropped. This is the most likely cause of the dropped traffic.

Quick reference

Asymmetric Encryption Algorithm Comparison

AlgorithmKey ExchangeSignaturesEquivalent Security KeyNotes
RSA-3072YesYes128-bitWidely deployed; slow for bulk data
ECDSA P-256NoYes128-bitFast signatures; standard TLS certs
ECDH / ECDHEYesNo128-bitPerfect forward secrecy in TLS 1.3
DH / DHEYesNo128-bit (3072-bit key)Replaced by ECDHE in modern TLS
Ed25519NoYes~128-bitSSH keys, modern PKI

About these practice questions

This 300-410 question is part of Courseiva's 1,401-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.