Courseiva
hardMultiple Choice

300-410 Practice Question: An engineer configures unicast Reverse Path…

An engineer configures unicast Reverse Path Forwarding (uRPF) in strict mode on an interface connected to a service provider. The router has a default route pointing to the ISP. Traffic from the ISP is being dropped by uRPF. Which is the most likely explanation?

⚠ Common exam trap

The trap here is assuming strict uRPF automatically trusts the default route — candidates forget that strict mode ignores 0.0.0.0/0 unless 'allow-default' is explicitly configured.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Strict mode uRPF does not use the default route for verification unless the 'allow-default' option is enabled.

Strict mode uRPF verifies that the source IP of an incoming packet is reachable via the same interface it arrived on, using the routing table. By default, strict uRPF does not consider the default route (0.0.0.0/0) as a valid return path, so traffic from the ISP whose return path is only the default route fails the check and is dropped. Enabling the 'allow-default' option (or using loose mode) permits the default route to satisfy the RPF check.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Strict mode uRPF does not use the default route for verification unless the 'allow-default' option is enabled.

    Why this is correct

    Strict mode uRPF verifies the source against the routing table and discards packets whose source is reachable only via the default route. Enabling 'allow-default' permits that verification, so ISP traffic sourced from addresses covered solely by the default route is dropped without it.

  • ✗

    The interface is configured with the wrong IP address, causing uRPF to fail.

    Why it's wrong here

    An incorrect interface address would break connectivity entirely, not selectively drop ISP-sourced packets while other traffic passes. Strict uRPF fails because the source's return path resolves via the default route, not the receiving interface. Wrong addressing is a Layer 3 misconfiguration, diagnosed by ping and adjacency checks.

  • ✗

    uRPF should be configured in loose mode to work with default routes.

    Why it's wrong here

    Loose mode checks only that a return path exists, so it would accept traffic, but it weakens the anti-spoofing guarantee strict mode provides. It is tempting because default routes break strict checks. The real cause is strict uRPF failing when the only return path is the default route, not the ISP link.

  • ✗

    The router has multiple default routes, causing uRPF to fail.

    Why it's wrong here

    Strict uRPF checks that the source address is reachable via the same interface it arrived on. A single default route already breaks this, since the reverse lookup returns the default rather than the specific ISP path; multiple defaults change nothing. Multiple defaults matter only for load-sharing or floating-static designs.

About these practice questions

Courseiva writes every 300-410 question from scratch — 1,401 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.