mediumMultiple Choice
300-410 Practice Question: Runs the following command on Router R1: R1# show…
A network engineer runs the following command on Router R1:
R1# show ipv6 interface tunnel 0
Tunnel0 is up, line protocol is up IPv6 is enabled, link-local address is FE80::1 Global unicast address(es): 2001:DB8:2::1, subnet is 2001:DB8:2::/64 Joined group address(es): FF02::1 FF02::2 ICMP redirects are enabled ICMP unreachables are enabled ND DAD is enabled, number of DAD attempts: 1 ND reachable time is 30000 milliseconds IPv6 uRPF: loose mode (allow default route)
Based on this output, what is the uRPF configuration on this interface?
⚠ Common exam trap
Cisco often tests the distinction between uRPF strict and loose modes by showing output that includes 'loose mode' or 'allow default route', and the trap here is that candidates may confuse 'loose mode' with 'disabled' or incorrectly assume that uRPF only applies to IPv4, ignoring the IPv6-specific output.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
uRPF is enabled in loose mode
The output explicitly shows 'IPv6 uRPF: loose mode (allow default route)', which confirms that unicast Reverse Path Forwarding (uRPF) is enabled in loose mode. In loose mode, the router checks that the source address of an incoming packet has a matching entry in the routing table, but it does not require the incoming interface to match the best return path. This is distinct from strict mode, which requires both a routing table entry and that the incoming interface is the same as the outgoing interface for the return route.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
uRPF is disabled
Why it's wrong here
Loose-mode uRPF is explicitly enabled on Tunnel0, so claiming it is disabled contradicts the output line "IPv6 uRPF: loose mode". Disabled uRPF would show no such entry, or "strict mode" would appear instead. This option tempts engineers who assume tunnels cannot run uRPF, yet disabled is the correct answer only when the interface lacks any uRPF line.
- ✗
uRPF is enabled in strict mode
Why it's wrong here
Strict mode requires a matching route back out the same interface, but the output explicitly states loose mode, which only checks that a route to the source exists in the routing table. Strict mode is tempting because it is the default recommendation for single-homed, symmetrically routed interfaces, where it blocks spoofed packets effectively.
- ✓
uRPF is enabled in loose mode
Why this is correct
The output line "IPv6 uRPF: loose mode (allow default route)" explicitly states the configuration. Loose mode verifies only that the source address is reachable via any route, unlike strict mode, which requires the source be reachable through the receiving interface.
- ✗
uRPF is enabled but only for IPv4
Why it's wrong here
The output explicitly reports "IPv6 uRPF: loose mode", so IPv6 unicast RPF is configured on Tunnel0; an IPv4-only deployment would not appear in `show ipv6 interface` output at all. It tempts because uRPF is commonly deployed for IPv4 anti-spoofing, where strict or loose mode on IPv4 interfaces would indeed be the correct configuration.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 1,401 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.