Courseiva
Infrastructure Security →mediumMultiple Select

300-410 Infrastructure Security Practice Question

A network engineer is implementing Unicast Reverse Path Forwarding (uRPF) on a Cisco IOS router to mitigate IP spoofing. The router has two interfaces: GigabitEthernet0/0 (WAN) and GigabitEthernet0/1 (LAN). The engineer wants to apply strict mode uRPF on the WAN interface and loose mode uRPF on the LAN interface. Which two commands are required to accomplish this? (Choose two.)

⚠ Common exam trap

The trap here is mixing up the keywords rx and any, which correspond to strict and loose modes respectively.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

interface GigabitEthernet0/0, then ip verify unicast source reachable-via rx

The correct commands are to enable strict mode uRPF on the WAN interface with ip verify unicast source reachable-via rx, and loose mode uRPF on the LAN interface with ip verify unicast source reachable-via any. These configurations match the requirement of strict on WAN and loose on LAN, providing effective anti-spoofing while accommodating asymmetric routing on the LAN.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    interface GigabitEthernet0/0, then ip verify unicast source reachable-via rx

    Why this is correct

    This command enables strict mode uRPF on the WAN interface. Strict mode checks that the source IP address is reachable via the same interface the packet was received on. This is appropriate for WAN interfaces where symmetric routing is expected, and it helps prevent spoofed packets from entering the network.

  • ✓

    interface GigabitEthernet0/1, then ip verify unicast source reachable-via any

    Why this is correct

    This command enables loose mode uRPF on the LAN interface. Loose mode checks that the source IP address is reachable via any interface in the routing table, not necessarily the receiving interface. This is suitable for LAN interfaces where asymmetric routing may occur, and it still provides some spoofing protection.

  • ✗

    interface GigabitEthernet0/0, then ip verify unicast source reachable-via any

    Why it's wrong here

    This would enable loose mode uRPF on the WAN interface, but the requirement is strict mode on WAN. Loose mode on WAN would allow packets with source addresses reachable via any interface, which is less strict and may not effectively mitigate spoofing from the WAN. Thus, it is incorrect.

  • ✗

    interface GigabitEthernet0/1, then ip verify unicast source reachable-via rx

    Why it's wrong here

    This would enable strict mode uRPF on the LAN interface, but the requirement is to use loose mode on the LAN. Strict mode on LAN could cause legitimate traffic to be dropped if asymmetric routing exists. Therefore, this command does not meet the requirement.

  • ✗

    ip verify unicast source reachable-via rx allow-default

    Why it's wrong here

    This command is used in strict mode with the allow-default option, which permits packets if the source is reachable via the default route. However, it is not specified for either interface in the scenario, and the requirement is to use strict on WAN and loose on LAN without allow-default. So it is not required.

Quick reference

Asymmetric Encryption Algorithm Comparison

AlgorithmKey ExchangeSignaturesEquivalent Security KeyNotes
RSA-3072YesYes128-bitWidely deployed; slow for bulk data
ECDSA P-256NoYes128-bitFast signatures; standard TLS certs
ECDH / ECDHEYesNo128-bitPerfect forward secrecy in TLS 1.3
DH / DHEYesNo128-bit (3072-bit key)Replaced by ECDHE in modern TLS
Ed25519NoYes~128-bitSSH keys, modern PKI

About these practice questions

This 300-410 question is part of Courseiva's 1,401-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.