Courseiva
hardMultiple Choice

300-410 Practice Question: A router is configured with uRPF (Unicast Reverse…

A router is configured with uRPF (Unicast Reverse Path Forwarding) in strict mode on an interface that belongs to a VRF. The network uses asymmetric routing for load balancing. The engineer notices that legitimate traffic from a customer is being dropped. Which is the most likely explanation?

⚠ Common exam trap

Many candidates confuse strict and loose uRPF behavior — candidates often assume loose mode is the default or that any route existence satisfies strict mode, when strict mode specifically requires the ingress interface to match the reverse path.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The uRPF strict mode requires that the source IP address be reachable via the same interface, but asymmetric routing causes the return path to use a different interface.

Strict uRPF requires that the router's reverse-path lookup for the packet's source IP resolve out the same interface the packet arrived on. With asymmetric routing, the return path to the customer is via a different interface than the one receiving the traffic, so the strict check fails and the packet is dropped. This is the classic failure mode of strict uRPF in multi-path or load-balanced designs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The uRPF strict mode requires that the source IP address be reachable via the same interface, but asymmetric routing causes the return path to use a different interface.

    Why this is correct

    Strict uRPF verifies the source address is reachable via the same interface the packet arrived on. Asymmetric routing sends return traffic through a different interface, so the reverse-path lookup fails and legitimate customer packets are dropped despite valid forwarding.

  • ✗

    The uRPF loose mode is configured instead of strict mode, which only checks that a route exists for the source IP, not the interface.

    Why it's wrong here

    Loose mode permits traffic whenever any route to the source exists, so it would not cause these drops. Strict mode drops packets whose reverse path exits a different interface than they arrived on, which asymmetric load balancing produces. This option would be correct if the interface were configured with 'ip verify unicast source reachable-via any'.

  • ✗

    The VRF has a default route that points to the incoming interface, causing uRPF to always succeed.

    Why it's wrong here

    A default route pointing out the incoming interface makes strict uRPF succeed for every source, so it cannot explain drops. Strict mode fails when the reverse path to the source leaves via a different interface, which asymmetric load balancing causes. This option would be correct if the symptom were traffic being permitted unexpectedly.

  • ✗

    The 'ip verify unicast source reachable-via any' command is used, which is the loose mode, not strict.

    Why it's wrong here

    Loose mode checks only that a route to the source exists in the routing table, ignoring the incoming interface, so it would not drop this traffic. Strict mode fails because the return path differs from the arrival interface under asymmetric routing. This option would be correct if the configuration genuinely used 'reachable-via any'.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

Quick reference

Asymmetric Encryption Algorithm Comparison

AlgorithmKey ExchangeSignaturesEquivalent Security KeyNotes
RSA-3072YesYes128-bitWidely deployed; slow for bulk data
ECDSA P-256NoYes128-bitFast signatures; standard TLS certs
ECDH / ECDHEYesNo128-bitPerfect forward secrecy in TLS 1.3
DH / DHEYesNo128-bit (3072-bit key)Replaced by ECDHE in modern TLS
Ed25519NoYes~128-bitSSH keys, modern PKI

Go deeper

Related to this question

About these practice questions

Courseiva writes every 300-410 question from scratch — 1,401 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.