Courseiva
hardMultiple Choice

300-410 Practice Question: An engineer configures IPv6 uRPF strict mode on…

An engineer configures IPv6 uRPF strict mode on an interface that is used for both IPv6 traffic and OSPFv3 routing. The router is an ABR with multiple areas. OSPFv3 adjacencies form correctly, but some IPv6 data traffic is dropped. The show ipv6 interface command shows uRPF is enabled. Which is the most likely explanation?

⚠ Common exam trap

Cisco often tests the nuance that uRPF strict mode drops traffic when a default route points out a different interface, and candidates forget that the 'allow-default' keyword is necessary to permit such traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The router has a default route pointing to a different interface, and uRPF strict mode without 'allow-default' drops packets whose source address is reachable via the default route.

URPF strict mode on an interface checks that the source address of incoming packets is reachable via the same interface. If the router has a default route pointing to a different interface, packets sourced from addresses that are only reachable via that default route will fail the RPF check and be dropped. The 'allow-default' keyword is required to exempt packets whose source is reachable via a default route from this check.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The router has a default route pointing to a different interface, and uRPF strict mode without 'allow-default' drops packets whose source address is reachable via the default route.

    Why this is correct

    Strict uRPF checks that the source is reachable via the same interface the packet arrived on. A default route pointing elsewhere makes many legitimate sources fail that check, so traffic is dropped unless allow-default is configured to permit default-route reachability.

  • ✗

    OSPFv3 adjacencies use link-local addresses, which are not checked by uRPF, but data traffic uses global addresses that are incorrectly filtered by the OSPFv3 process.

    Why it's wrong here

    OSPFv3 does not filter data traffic; it only populates the routing table, and uRPF consults that table. Link-local addresses are checked by uRPF when they are the source. OSPFv3's link-local peering is relevant to adjacency formation, not to forwarding decisions on global-address traffic.

  • ✗

    The router has 'ipv6 uRPF allow-default' configured, but the default route is not installed, causing all traffic to be dropped.

    Why it's wrong here

    Strict uRPF drops traffic whose source fails the reverse-path lookup; an uninstalled default route only matters when allow-default is set, and even then it permits rather than drops. The option inverts the mechanism. Allow-default exists to accept traffic lacking a specific reverse path, useful on edge interfaces with a default route present.

  • ✗

    The interface has an IPv6 ACL that denies traffic from certain prefixes, overriding uRPF.

    Why it's wrong here

    An IPv6 ACL is evaluated as a separate feature and does not override uRPF; both must pass, so ACLs cannot mask uRPF drops. ACLs are the right tool when you need to permit or deny specific prefixes regardless of reachability, but here the drops stem from the strict reverse-path check on asymmetric paths.

Quick reference

Routing Protocol Comparison

ProtocolMetricMax HopsAlgorithmType
RIP v2Hop count15Bellman-FordDistance vector
OSPFCost (bandwidth)UnlimitedDijkstra (SPF)Link state
EIGRPComposite metricUnlimitedDUALHybrid
IS-ISCostUnlimitedDijkstraLink state
BGPPolicy / attributesUnlimitedPath vectorPath vector

RIP's 15-hop limit makes it unsuitable for large networks. OSPF and EIGRP dominate modern enterprise deployments.

About these practice questions

Courseiva writes every 300-410 question from scratch — 1,401 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.