Question 1,221 of 2,011
hardMultiple ChoiceObjective-mapped
300-410 Practice Question: An engineer configures unicast Reverse Path…
An engineer configures unicast Reverse Path Forwarding (uRPF) in strict mode on an interface. After the configuration, legitimate traffic from a customer network is being dropped. The engineer confirms that the route for the customer subnet exists in the routing table and points to the correct interface. What is the most likely explanation?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Asymmetric routing is in use, and the return route for the source IP points to a different interface.
Strict uRPF checks that the source IP address of an incoming packet has a route in the routing table that points back to the same interface. If the customer network uses asymmetric routing (i.e., traffic comes in one interface but the return route points out a different interface), strict uRPF will drop the traffic. The edge case is that even if the route exists, if it does not point to the incoming interface, the packet is dropped.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Asymmetric routing is in use, and the return route for the source IP points to a different interface.
Why this is correct
Strict uRPF requires that the best route to the source IP address points back to the same interface on which the packet was received. If asymmetric routing is present, the return path may be via a different interface, causing strict uRPF to drop the packet.
- ✗
The 'allow-default' option is not enabled, so default routes are not considered.
Why it's wrong here
The 'allow-default' option is used in loose mode to allow packets with source IPs that match a default route. In strict mode, default routes are not used for the check unless explicitly configured, but the question states the route exists, so this is not the issue.
- ✗
The 'ip verify unicast source reachable-via any' command was used instead of 'rx'
Why it's wrong here
Using 'any' enables loose mode, not strict mode. The question states strict mode is configured, so this is not the case.
- ✗
The customer subnet is a summary route, and the more specific route is missing.
Why it's wrong here
uRPF uses the best route in the routing table; if a summary route exists, it is used for the check. Missing more specific routes would not cause drops if the summary is present.
Visual reference
Quick reference
Asymmetric Encryption Algorithm Comparison
| Algorithm | Key Exchange | Signatures | Equivalent Security Key | Notes |
|---|---|---|---|---|
| RSA-3072 | Yes | Yes | 128-bit | Widely deployed; slow for bulk data |
| ECDSA P-256 | No | Yes | 128-bit | Fast signatures; standard TLS certs |
| ECDH / ECDHE | Yes | No | 128-bit | Perfect forward secrecy in TLS 1.3 |
| DH / DHE | Yes | No | 128-bit (3072-bit key) | Replaced by ECDHE in modern TLS |
| Ed25519 | No | Yes | ~128-bit | SSH keys, modern PKI |
About these practice questions
Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →
Last reviewed: Jun 18, 2026
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.
Question Discussion
Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.
Sign in to join the discussion.