300-410 Infrastructure Security Practice Question
A network engineer is configuring uRPF on a Cisco IOS router. The router has two interfaces: GigabitEthernet0/0 (WAN) and GigabitEthernet0/1 (LAN). The engineer wants to prevent spoofed packets from entering the WAN interface while allowing asymmetric routing. Which uRPF mode should be configured on GigabitEthernet0/0?
⚠ Common exam trap
The trap here is assuming that strict mode is always better for spoofing prevention, but it can break legitimate asymmetric routing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Loose mode
Loose mode uRPF allows asymmetric routing because it only checks that the source address is present in the routing table, regardless of the incoming interface. Strict mode would require the source to be reachable via the same interface, which would break asymmetric routing. Therefore, loose mode is correct.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Feasible path uRPF
Why it's wrong here
Feasible path uRPF is not a standard uRPF mode on Cisco IOS. Cisco supports strict and loose modes, and in some platforms, VRF-aware uRPF. Feasible path is a term used in other contexts, not a configuration option for uRPF on IOS routers.
- ✗
VRF mode
Why it's wrong here
VRF mode is not a uRPF mode. uRPF can be configured in a VRF-aware manner, but that is not a separate mode. The engineer needs to choose between strict and loose modes; VRF mode is not applicable to the requirement of allowing asymmetric routing.
- ✗
Strict mode
Why it's wrong here
Strict mode uRPF requires that the source address be reachable via the same interface it was received on. This would drop packets in an asymmetric routing scenario, where the return path may differ. Since the engineer wants to allow asymmetric routing, strict mode is not suitable.
- ✓
Loose mode
Why this is correct
Loose mode uRPF checks that the source address is reachable via any interface in the routing table, not necessarily the receiving interface. This allows asymmetric routing because the return path can be different. It still provides spoofing protection by ensuring the source is routable, making it the correct choice for this scenario.
Quick reference
Asymmetric Encryption Algorithm Comparison
| Algorithm | Key Exchange | Signatures | Equivalent Security Key | Notes |
|---|---|---|---|---|
| RSA-3072 | Yes | Yes | 128-bit | Widely deployed; slow for bulk data |
| ECDSA P-256 | No | Yes | 128-bit | Fast signatures; standard TLS certs |
| ECDH / ECDHE | Yes | No | 128-bit | Perfect forward secrecy in TLS 1.3 |
| DH / DHE | Yes | No | 128-bit (3072-bit key) | Replaced by ECDHE in modern TLS |
| Ed25519 | No | Yes | ~128-bit | SSH keys, modern PKI |
Go deeper
Related to this question
About these practice questions
Courseiva writes every 300-410 question from scratch — 1,401 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.