hardMultiple Choice
300-410 Practice Question: An engineer configures IPv6 uRPF strict mode on…
An engineer configures IPv6 uRPF strict mode on an interface that is used for both IPv6 traffic and OSPFv3 routing. The router is an ABR with multiple areas. OSPFv3 adjacencies form correctly, but some IPv6 data traffic is dropped. The show ipv6 interface command shows uRPF is enabled. Which is the most likely explanation?
⚠ Common exam trap
Cisco often tests the nuance that uRPF strict mode drops traffic when a default route points out a different interface, and candidates forget that the 'allow-default' keyword is necessary to permit such traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The router has a default route pointing to a different interface, and uRPF strict mode without 'allow-default' drops packets whose source address is reachable via the default route.
URPF strict mode on an interface checks that the source address of incoming packets is reachable via the same interface. If the router has a default route pointing to a different interface, packets sourced from addresses that are only reachable via that default route will fail the RPF check and be dropped. The 'allow-default' keyword is required to exempt packets whose source is reachable via a default route from this check.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The router has a default route pointing to a different interface, and uRPF strict mode without 'allow-default' drops packets whose source address is reachable via the default route.
Why this is correct
Strict uRPF checks that the source is reachable via the same interface the packet arrived on. A default route pointing elsewhere makes many legitimate sources fail that check, so traffic is dropped unless allow-default is configured to permit default-route reachability.
- ✗
OSPFv3 adjacencies use link-local addresses, which are not checked by uRPF, but data traffic uses global addresses that are incorrectly filtered by the OSPFv3 process.
Why it's wrong here
OSPFv3 does not filter data traffic; it only populates the routing table, and uRPF consults that table. Link-local addresses are checked by uRPF when they are the source. OSPFv3's link-local peering is relevant to adjacency formation, not to forwarding decisions on global-address traffic.
- ✗
The router has 'ipv6 uRPF allow-default' configured, but the default route is not installed, causing all traffic to be dropped.
Why it's wrong here
Strict uRPF drops traffic whose source fails the reverse-path lookup; an uninstalled default route only matters when allow-default is set, and even then it permits rather than drops. The option inverts the mechanism. Allow-default exists to accept traffic lacking a specific reverse path, useful on edge interfaces with a default route present.
- ✗
The interface has an IPv6 ACL that denies traffic from certain prefixes, overriding uRPF.
Why it's wrong here
An IPv6 ACL is evaluated as a separate feature and does not override uRPF; both must pass, so ACLs cannot mask uRPF drops. ACLs are the right tool when you need to permit or deny specific prefixes regardless of reachability, but here the drops stem from the strict reverse-path check on asymmetric paths.
Quick reference
Routing Protocol Comparison
| Protocol | Metric | Max Hops | Algorithm | Type |
|---|---|---|---|---|
| RIP v2 | Hop count | 15 | Bellman-Ford | Distance vector |
| OSPF | Cost (bandwidth) | Unlimited | Dijkstra (SPF) | Link state |
| EIGRP | Composite metric | Unlimited | DUAL | Hybrid |
| IS-IS | Cost | Unlimited | Dijkstra | Link state |
| BGP | Policy / attributes | Unlimited | Path vector | Path vector |
RIP's 15-hop limit makes it unsuitable for large networks. OSPF and EIGRP dominate modern enterprise deployments.
Go deeper
Related to this question
Learn chapter
Advanced EIGRP Features (Stub, Load Balancing, Named Mode)
Key term
uRPF
Unicast Reverse Path Forwarding is a network security feature that verifies the source address of incoming packets to prevent IP spoofing attacks.
Key term
IPv6 Routing OSPFv3
OSPFv3 is a routing protocol that lets routers share information about how to reach destinations in an IPv6 network, updating routes automatically as the network changes.
About these practice questions
Courseiva writes every 300-410 question from scratch — 1,401 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.