300-410 Infrastructure Security Practice Question
A network engineer is configuring Unicast Reverse Path Forwarding (uRPF) on a Cisco IOS router to mitigate spoofed source IP addresses. The router has two interfaces: GigabitEthernet0/0 connecting to an ISP (untrusted) and GigabitEthernet0/1 connecting to the internal network. The engineer wants to ensure that uRPF is applied only to traffic entering from the ISP. Which configuration mode and command should be used?
⚠ Common exam trap
Candidates often confuse strict and loose uRPF modes, or applying uRPF to the wrong interface, which would not effectively mitigate spoofed traffic from the untrusted ISP.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Interface configuration mode on GigabitEthernet0/0, using 'ip verify unicast source reachable-via rx'.
Strict uRPF is configured on the ingress interface facing the untrusted network using the 'ip verify unicast source reachable-via rx' command. This ensures that the source IP address of incoming packets is reachable via the same interface, effectively dropping spoofed packets. Applying it to the ISP-facing interface (GigabitEthernet0/0) meets the requirement of filtering traffic entering from the ISP.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Global configuration mode, using 'ip verify unicast source reachable-via any'.
Why it's wrong here
The 'ip verify unicast source reachable-via any' command enables loose uRPF, which only checks if the source is reachable via any interface, not necessarily the ingress interface. It is less strict and does not provide the same level of spoofing mitigation as strict mode. Additionally, uRPF is applied per interface, not globally, so this command in global configuration mode is invalid.
- ✗
Interface configuration mode on GigabitEthernet0/1, using 'ip verify unicast source reachable-via rx'.
Why it's wrong here
Applying uRPF to the internal interface (GigabitEthernet0/1) would check source addresses of internal traffic, which is not the goal. The requirement is to filter traffic entering from the untrusted ISP. Internal sources are typically legitimate and reachable via the internal interface, so strict uRPF there would not mitigate external spoofing and could cause issues if asymmetric routing exists internally.
- ✗
Interface configuration mode on GigabitEthernet0/0, using 'ip verify unicast source reachable-via any'.
Why it's wrong here
While applying uRPF to the correct interface (GigabitEthernet0/0), using 'reachable-via any' enables loose mode, which only verifies that the source is reachable via any route in the routing table. This is weaker than strict mode and may allow spoofed packets if a route to the spoofed source exists. The requirement implies strict spoofing mitigation, so strict mode (rx) is preferred.
- ✓
Interface configuration mode on GigabitEthernet0/0, using 'ip verify unicast source reachable-via rx'.
Why this is correct
The command 'ip verify unicast source reachable-via rx' enables strict uRPF, which checks that the source IP is reachable via the same interface the packet was received on. Applying it to the ISP-facing interface (GigabitEthernet0/0) is correct because that is where spoofed traffic would enter. This configuration mitigates spoofing by dropping packets whose source is not reachable through the ISP interface.
Visual reference
Go deeper
Related to this question
About these practice questions
This 300-410 question is part of Courseiva's 1,401-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.