Courseiva
Infrastructure Security →hardMultiple Choice

300-410 Infrastructure Security Practice Question

A network engineer is implementing Unicast Reverse Path Forwarding (uRPF) on a Cisco IOS router to mitigate spoofed source IP addresses. The router has two interfaces: GigabitEthernet0/0 connected to the Internet, and GigabitEthernet0/1 connected to the internal network. The engineer wants to ensure that packets coming from the Internet are dropped if their source IP address is not reachable via the same interface. However, the internal network uses asymmetric routing, so strict uRPF cannot be used on the internal interface. Which configuration should be applied to GigabitEthernet0/0 to achieve the goal?

⚠ Common exam trap

Many exam-takers confuse strict and loose uRPF modes; strict mode uses 'rx' and checks the same interface, while loose mode uses 'any' and checks any interface.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ip verify unicast source reachable-via rx

Strict uRPF is configured with the 'ip verify unicast source reachable-via rx' command, which verifies that the source IP address is reachable via the same interface the packet was received on. This is ideal for the Internet-facing interface to prevent spoofing. Loose mode ('any') would not meet the requirement, and the other options include modifiers or incorrect keywords.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    ip verify unicast source reachable-via rx allow-default

    Why it's wrong here

    The 'allow-default' option permits packets whose source address matches the default route. This weakens the strict check and is typically used when a default route exists. The scenario does not mention a default route, and the goal is strict checking, so this is not appropriate.

  • ✗

    ip verify unicast source reachable-via tx

    Why it's wrong here

    The 'tx' keyword is used for uRPF in a different context, such as when the router is the source of the traffic. For uRPF on an incoming interface, the correct keyword is 'rx'. The 'tx' option is not valid for this purpose.

  • ✓

    ip verify unicast source reachable-via rx

    Why this is correct

    The 'ip verify unicast source reachable-via rx' command enables strict uRPF, which checks that the source IP address is reachable via the same interface the packet was received on. This is appropriate for the Internet-facing interface to drop spoofed packets. The internal interface would need a different mode due to asymmetric routing.

  • ✗

    ip verify unicast source reachable-via any

    Why it's wrong here

    The 'any' keyword enables loose uRPF, which checks if the source is reachable via any interface. This is less strict and would not drop packets with spoofed source addresses that are reachable via other interfaces. The requirement is to drop packets not reachable via the same interface, so strict mode is needed.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

Courseiva writes every 300-410 question from scratch — 1,401 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.