Courseiva
Infrastructure Security →easyMultiple Choice

300-410 Infrastructure Security Practice Question

A network engineer is configuring Unicast Reverse Path Forwarding (uRPF) on a Cisco IOS router to mitigate spoofed source IP addresses. The engineer wants to allow traffic from a multihomed customer that uses asymmetric routing. Which uRPF mode should the engineer configure?

⚠ Common exam trap

The trap here is assuming that strict mode is always the most secure choice, but it breaks asymmetric routing, which is common in multihomed environments.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Loose mode

Loose mode uRPF verifies that the source IP address is reachable via any interface in the routing table, making it suitable for asymmetric routing scenarios. Strict mode would drop legitimate packets because it requires the source to be reachable via the receiving interface. Loose mode still provides anti-spoofing benefits by ensuring the source prefix exists in the routing table.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Strict mode

    Why it's wrong here

    Strict mode requires that the source IP address be reachable via the same interface on which the packet was received. In an asymmetric routing scenario, return traffic may arrive on a different interface, causing strict mode to drop legitimate packets. Therefore, strict mode is not suitable for multihomed customers with asymmetric routing.

  • ✗

    VRF mode

    Why it's wrong here

    VRF mode is used when uRPF is applied in a VRF context, but it still operates in strict or loose mode within that VRF. It does not inherently support asymmetric routing across different VRFs. For a multihomed customer with asymmetric routing in the global table, loose mode is the appropriate choice, not VRF mode.

  • ✓

    Loose mode

    Why this is correct

    Loose mode checks that the source IP address is reachable via any interface in the routing table, not necessarily the receiving interface. This allows packets from multihomed customers using asymmetric routing to pass, as long as the source is reachable. It still provides some anti-spoofing protection by verifying the source prefix exists in the routing table.

  • ✗

    Feasible path mode

    Why it's wrong here

    Feasible path mode is not a standard uRPF mode on Cisco IOS. Cisco supports strict and loose modes, and in some platforms, a VRF mode. Feasible path is a concept in BGP, not uRPF. Therefore, this option is incorrect and would not be a valid configuration choice.

Quick reference

Asymmetric Encryption Algorithm Comparison

AlgorithmKey ExchangeSignaturesEquivalent Security KeyNotes
RSA-3072YesYes128-bitWidely deployed; slow for bulk data
ECDSA P-256NoYes128-bitFast signatures; standard TLS certs
ECDH / ECDHEYesNo128-bitPerfect forward secrecy in TLS 1.3
DH / DHEYesNo128-bit (3072-bit key)Replaced by ECDHE in modern TLS
Ed25519NoYes~128-bitSSH keys, modern PKI

About these practice questions

Courseiva writes every 300-410 question from scratch — 1,401 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.