300-410 Infrastructure Security Practice Question
A network engineer is configuring Unicast Reverse Path Forwarding (uRPF) on a Cisco IOS router to mitigate spoofed source IP addresses. The engineer wants to allow traffic from a multihomed customer that uses asymmetric routing. Which uRPF mode should the engineer configure?
⚠ Common exam trap
The trap here is assuming that strict mode is always the most secure choice, but it breaks asymmetric routing, which is common in multihomed environments.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Loose mode
Loose mode uRPF verifies that the source IP address is reachable via any interface in the routing table, making it suitable for asymmetric routing scenarios. Strict mode would drop legitimate packets because it requires the source to be reachable via the receiving interface. Loose mode still provides anti-spoofing benefits by ensuring the source prefix exists in the routing table.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Strict mode
Why it's wrong here
Strict mode requires that the source IP address be reachable via the same interface on which the packet was received. In an asymmetric routing scenario, return traffic may arrive on a different interface, causing strict mode to drop legitimate packets. Therefore, strict mode is not suitable for multihomed customers with asymmetric routing.
- ✗
VRF mode
Why it's wrong here
VRF mode is used when uRPF is applied in a VRF context, but it still operates in strict or loose mode within that VRF. It does not inherently support asymmetric routing across different VRFs. For a multihomed customer with asymmetric routing in the global table, loose mode is the appropriate choice, not VRF mode.
- ✓
Loose mode
Why this is correct
Loose mode checks that the source IP address is reachable via any interface in the routing table, not necessarily the receiving interface. This allows packets from multihomed customers using asymmetric routing to pass, as long as the source is reachable. It still provides some anti-spoofing protection by verifying the source prefix exists in the routing table.
- ✗
Feasible path mode
Why it's wrong here
Feasible path mode is not a standard uRPF mode on Cisco IOS. Cisco supports strict and loose modes, and in some platforms, a VRF mode. Feasible path is a concept in BGP, not uRPF. Therefore, this option is incorrect and would not be a valid configuration choice.
Quick reference
Asymmetric Encryption Algorithm Comparison
| Algorithm | Key Exchange | Signatures | Equivalent Security Key | Notes |
|---|---|---|---|---|
| RSA-3072 | Yes | Yes | 128-bit | Widely deployed; slow for bulk data |
| ECDSA P-256 | No | Yes | 128-bit | Fast signatures; standard TLS certs |
| ECDH / ECDHE | Yes | No | 128-bit | Perfect forward secrecy in TLS 1.3 |
| DH / DHE | Yes | No | 128-bit (3072-bit key) | Replaced by ECDHE in modern TLS |
| Ed25519 | No | Yes | ~128-bit | SSH keys, modern PKI |
Go deeper
Related to this question
About these practice questions
Courseiva writes every 300-410 question from scratch — 1,401 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.