300-410 Infrastructure Security Practice Question
A network engineer is implementing Unicast Reverse Path Forwarding (uRPF) on a Cisco IOS router to mitigate IP spoofing. The router has two interfaces: GigabitEthernet0/0 (WAN) and GigabitEthernet0/1 (LAN). The engineer wants to apply strict mode uRPF on the WAN interface and loose mode uRPF on the LAN interface. Which two commands are required to accomplish this? (Choose two.)
⚠ Common exam trap
The trap here is mixing up the keywords rx and any, which correspond to strict and loose modes respectively.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
interface GigabitEthernet0/0, then ip verify unicast source reachable-via rx
The correct commands are to enable strict mode uRPF on the WAN interface with ip verify unicast source reachable-via rx, and loose mode uRPF on the LAN interface with ip verify unicast source reachable-via any. These configurations match the requirement of strict on WAN and loose on LAN, providing effective anti-spoofing while accommodating asymmetric routing on the LAN.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
interface GigabitEthernet0/0, then ip verify unicast source reachable-via rx
Why this is correct
This command enables strict mode uRPF on the WAN interface. Strict mode checks that the source IP address is reachable via the same interface the packet was received on. This is appropriate for WAN interfaces where symmetric routing is expected, and it helps prevent spoofed packets from entering the network.
- ✓
interface GigabitEthernet0/1, then ip verify unicast source reachable-via any
Why this is correct
This command enables loose mode uRPF on the LAN interface. Loose mode checks that the source IP address is reachable via any interface in the routing table, not necessarily the receiving interface. This is suitable for LAN interfaces where asymmetric routing may occur, and it still provides some spoofing protection.
- ✗
interface GigabitEthernet0/0, then ip verify unicast source reachable-via any
Why it's wrong here
This would enable loose mode uRPF on the WAN interface, but the requirement is strict mode on WAN. Loose mode on WAN would allow packets with source addresses reachable via any interface, which is less strict and may not effectively mitigate spoofing from the WAN. Thus, it is incorrect.
- ✗
interface GigabitEthernet0/1, then ip verify unicast source reachable-via rx
Why it's wrong here
This would enable strict mode uRPF on the LAN interface, but the requirement is to use loose mode on the LAN. Strict mode on LAN could cause legitimate traffic to be dropped if asymmetric routing exists. Therefore, this command does not meet the requirement.
- ✗
ip verify unicast source reachable-via rx allow-default
Why it's wrong here
This command is used in strict mode with the allow-default option, which permits packets if the source is reachable via the default route. However, it is not specified for either interface in the scenario, and the requirement is to use strict on WAN and loose on LAN without allow-default. So it is not required.
Quick reference
Asymmetric Encryption Algorithm Comparison
| Algorithm | Key Exchange | Signatures | Equivalent Security Key | Notes |
|---|---|---|---|---|
| RSA-3072 | Yes | Yes | 128-bit | Widely deployed; slow for bulk data |
| ECDSA P-256 | No | Yes | 128-bit | Fast signatures; standard TLS certs |
| ECDH / ECDHE | Yes | No | 128-bit | Perfect forward secrecy in TLS 1.3 |
| DH / DHE | Yes | No | 128-bit (3072-bit key) | Replaced by ECDHE in modern TLS |
| Ed25519 | No | Yes | ~128-bit | SSH keys, modern PKI |
Go deeper
Related to this question
About these practice questions
This 300-410 question is part of Courseiva's 1,401-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.