Courseiva
hardMultiple ChoiceObjective-mapped

300-410 Practice Question: Configures an EEM applet to monitor uRPF (Unicast…

A network engineer configures an EEM applet to monitor uRPF (Unicast Reverse Path Forwarding) failures using the event syslog pattern 'IP-3-URPF'. The applet is designed to log when uRPF drops packets due to strict mode. The network has asymmetric routing, and packets are dropped. The EEM applet does not trigger. Which is the most likely explanation?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

uRPF strict mode drops packets silently without generating a syslog message unless the 'log' keyword is used.

uRPF strict mode drops packets when the source IP address is not reachable via the incoming interface. However, the syslog message 'IP-3-URPF' is generated only when the 'ip verify unicast source reachable-via' command is configured with the 'allow-default' option or when the drop is logged explicitly. In strict mode without 'allow-default', the router may drop packets silently without generating a syslog message, especially if the drop is due to asymmetric routing. The EEM applet will not trigger because no syslog is generated for the drop.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • uRPF strict mode drops packets silently without generating a syslog message unless the 'log' keyword is used.

    Why this is correct

    Correct. uRPF drops are not logged by default; the 'log' keyword must be added to the verification command.

  • The EEM applet must use 'event routing' to capture uRPF events.

    Why it's wrong here

    EEM does not have a native routing event trigger for uRPF.

  • Asymmetric routing causes uRPF to generate a different syslog pattern, such as 'IP-4-URPF'.

    Why it's wrong here

    The severity may vary, but without logging, no syslog is generated.

  • The uRPF must be configured in loose mode to generate syslog messages.

    Why it's wrong here

    Loose mode also requires logging to generate syslog.

Quick reference

Asymmetric Encryption Algorithm Comparison

AlgorithmKey ExchangeSignaturesEquivalent Security KeyNotes
RSA-3072YesYes128-bitWidely deployed; slow for bulk data
ECDSA P-256NoYes128-bitFast signatures; standard TLS certs
ECDH / ECDHEYesNo128-bitPerfect forward secrecy in TLS 1.3
DH / DHEYesNo128-bit (3072-bit key)Replaced by ECDHE in modern TLS
Ed25519NoYes~128-bitSSH keys, modern PKI

About these practice questions

One of 1,966 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.