300-410 Infrastructure Security Practice Question
A network engineer is implementing Unicast Reverse Path Forwarding (uRPF) on a Cisco IOS XE router to mitigate spoofed source IP addresses. The router has two interfaces: GigabitEthernet0/0 (WAN, connected to ISP) and GigabitEthernet0/1 (LAN, connected to internal network). The engineer wants to apply strict uRPF on the WAN interface to drop packets with spoofed source addresses, but the internal network uses asymmetric routing, with some return traffic going out a different interface. The engineer applies the following configuration:
interface GigabitEthernet0/0 ip address 203.0.113.1 255.255.255.0 ip verify unicast source reachable-via rx
After applying this, the engineer notices that some legitimate traffic from the internal network is being dropped. Which action should the engineer take to resolve the issue while maintaining spoofing protection?
⚠ Common exam trap
The trap here is thinking that loose mode is the only way to handle asymmetric routing, when in fact strict mode with an exception ACL can maintain stronger security for most traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure uRPF with an access list to allow specific internal subnets that are subject to asymmetric routing, while keeping strict mode for other traffic.
Strict uRPF drops packets if the source address is not reachable via the incoming interface. Asymmetric routing causes legitimate return traffic to arrive on an interface different from the one used to reach the source, triggering drops. Cisco IOS XE allows an access list with strict uRPF to exempt specific source addresses from the check. By permitting the internal subnets that use asymmetric routing in the ACL, the engineer maintains strict uRPF for all other traffic, preserving spoofing protection while allowing legitimate flows.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure uRPF with an access list to allow specific internal subnets that are subject to asymmetric routing, while keeping strict mode for other traffic.
Why this is correct
Cisco IOS XE supports uRPF with an access list (ip verify unicast source reachable-via rx allow-self-ping acl) to exempt certain source addresses from the strict check. By creating an ACL that permits the internal subnets experiencing asymmetric routing, the engineer can maintain strict uRPF for all other traffic, preserving spoofing protection while allowing legitimate asymmetric flows. This is the recommended approach for handling exceptions without weakening overall security.
- ✗
Enable uRPF in loose mode with an access list that denies known spoofed prefixes, and apply it to the WAN interface.
Why it's wrong here
Loose mode with an ACL denying known spoofed prefixes still allows any other source address that is routable, which is less secure than strict mode. The engineer wants to maintain strong spoofing protection, and strict mode with an exception ACL is more precise. This option weakens protection by default and relies on manually maintained deny lists, which may not be comprehensive. It does not address the asymmetric routing issue as cleanly as an allow ACL in strict mode.
- ✗
Disable uRPF on the WAN interface and instead implement IP Source Guard on the LAN interfaces to prevent spoofing.
Why it's wrong here
Disabling uRPF on the WAN interface removes protection against spoofed packets entering from the ISP. IP Source Guard on LAN interfaces is useful for preventing spoofing within the LAN but does not protect against spoofed traffic from the WAN. The engineer needs to maintain WAN protection, so this approach is insufficient. A combination might be used, but the immediate issue is the drop of legitimate traffic due to strict uRPF.
- ✗
Change the uRPF mode to loose mode by using the ip verify unicast source reachable-via any command on the WAN interface.
Why it's wrong here
Loose mode uRPF checks if the source address is reachable via any route in the routing table, not necessarily the incoming interface. While this would allow asymmetric traffic, it significantly weakens spoofing protection because spoofed packets with any routable source address would be permitted. The engineer wants to maintain spoofing protection, so loose mode is not the best choice. A more targeted solution is needed.
Visual reference
Quick reference
Asymmetric Encryption Algorithm Comparison
| Algorithm | Key Exchange | Signatures | Equivalent Security Key | Notes |
|---|---|---|---|---|
| RSA-3072 | Yes | Yes | 128-bit | Widely deployed; slow for bulk data |
| ECDSA P-256 | No | Yes | 128-bit | Fast signatures; standard TLS certs |
| ECDH / ECDHE | Yes | No | 128-bit | Perfect forward secrecy in TLS 1.3 |
| DH / DHE | Yes | No | 128-bit (3072-bit key) | Replaced by ECDHE in modern TLS |
| Ed25519 | No | Yes | ~128-bit | SSH keys, modern PKI |
Go deeper
Related to this question
About these practice questions
One of 1,401 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.