300-410 Infrastructure Security Practice Question
A network engineer is configuring Unicast Reverse Path Forwarding (uRPF) on a Cisco IOS router to mitigate spoofed source IP addresses. The engineer wants to ensure that packets are dropped if the source IP address is not reachable via the same interface they arrived on. The engineer configures 'ip verify unicast source reachable-via rx' on interface GigabitEthernet0/0. However, some legitimate traffic from a secondary path is being dropped. What is the most likely cause?
⚠ Common exam trap
Candidates often confuse strict and loose uRPF modes; 'rx' means strict, which is sensitive to asymmetric routing, while 'any' means loose.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The router uses strict uRPF, which requires the source to be reachable via the same interface; asymmetric routing causes legitimate packets to be dropped.
The 'reachable-via rx' option enables strict uRPF, which drops packets if the source IP is not reachable via the ingress interface. In networks with asymmetric routing, legitimate traffic may arrive on an interface that is not the best path back to the source, causing drops. Switching to loose uRPF ('reachable-via any') would alleviate this but reduce spoofing protection. CEF is typically enabled by default, so it is not the issue.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The interface must be configured with 'ip verify unicast source reachable-via any' to allow asymmetric routing.
Why it's wrong here
Configuring 'reachable-via any' would enable loose uRPF, which would allow the asymmetric traffic. However, this changes the security posture and is not the cause of the current drops. The question asks for the most likely cause of the drops, which is the strict mode itself, not a missing configuration.
- ✗
The uRPF feature requires CEF to be enabled, and CEF is not enabled on the router.
Why it's wrong here
uRPF relies on Cisco Express Forwarding (CEF) to perform the reverse path lookup. However, CEF is enabled by default on modern Cisco IOS routers. If CEF were disabled, uRPF would not function at all, but the scenario indicates some traffic is dropped, implying uRPF is active. Thus, CEF being disabled is unlikely.
- ✗
The router uses loose uRPF, which only checks if the source is reachable via any interface, so it should not drop legitimate traffic.
Why it's wrong here
Loose uRPF is configured with 'reachable-via any', not 'rx'. The 'rx' keyword specifically enables strict mode. Loose uRPF would not drop packets solely due to asymmetric routing, so this option misidentifies the mode and the cause.
- ✓
The router uses strict uRPF, which requires the source to be reachable via the same interface; asymmetric routing causes legitimate packets to be dropped.
Why this is correct
The 'reachable-via rx' option enables strict uRPF, which checks that the source IP is reachable via the same interface the packet arrived on. In asymmetric routing scenarios, where return traffic takes a different path, legitimate packets can be dropped. This is the most likely cause of the dropped traffic.
Quick reference
Asymmetric Encryption Algorithm Comparison
| Algorithm | Key Exchange | Signatures | Equivalent Security Key | Notes |
|---|---|---|---|---|
| RSA-3072 | Yes | Yes | 128-bit | Widely deployed; slow for bulk data |
| ECDSA P-256 | No | Yes | 128-bit | Fast signatures; standard TLS certs |
| ECDH / ECDHE | Yes | No | 128-bit | Perfect forward secrecy in TLS 1.3 |
| DH / DHE | Yes | No | 128-bit (3072-bit key) | Replaced by ECDHE in modern TLS |
| Ed25519 | No | Yes | ~128-bit | SSH keys, modern PKI |
Go deeper
Related to this question
About these practice questions
This 300-410 question is part of Courseiva's 1,401-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.