hardMultiple Choice
300-410 Practice Question: A router is configured with uRPF (Unicast Reverse…
A router is configured with uRPF (Unicast Reverse Path Forwarding) in strict mode on an interface that belongs to a VRF. The network uses asymmetric routing for load balancing. The engineer notices that legitimate traffic from a customer is being dropped. Which is the most likely explanation?
⚠ Common exam trap
Many candidates confuse strict and loose uRPF behavior — candidates often assume loose mode is the default or that any route existence satisfies strict mode, when strict mode specifically requires the ingress interface to match the reverse path.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The uRPF strict mode requires that the source IP address be reachable via the same interface, but asymmetric routing causes the return path to use a different interface.
Strict uRPF requires that the router's reverse-path lookup for the packet's source IP resolve out the same interface the packet arrived on. With asymmetric routing, the return path to the customer is via a different interface than the one receiving the traffic, so the strict check fails and the packet is dropped. This is the classic failure mode of strict uRPF in multi-path or load-balanced designs.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The uRPF strict mode requires that the source IP address be reachable via the same interface, but asymmetric routing causes the return path to use a different interface.
Why this is correct
Strict uRPF verifies the source address is reachable via the same interface the packet arrived on. Asymmetric routing sends return traffic through a different interface, so the reverse-path lookup fails and legitimate customer packets are dropped despite valid forwarding.
- ✗
The uRPF loose mode is configured instead of strict mode, which only checks that a route exists for the source IP, not the interface.
Why it's wrong here
Loose mode permits traffic whenever any route to the source exists, so it would not cause these drops. Strict mode drops packets whose reverse path exits a different interface than they arrived on, which asymmetric load balancing produces. This option would be correct if the interface were configured with 'ip verify unicast source reachable-via any'.
- ✗
The VRF has a default route that points to the incoming interface, causing uRPF to always succeed.
Why it's wrong here
A default route pointing out the incoming interface makes strict uRPF succeed for every source, so it cannot explain drops. Strict mode fails when the reverse path to the source leaves via a different interface, which asymmetric load balancing causes. This option would be correct if the symptom were traffic being permitted unexpectedly.
- ✗
The 'ip verify unicast source reachable-via any' command is used, which is the loose mode, not strict.
Why it's wrong here
Loose mode checks only that a route to the source exists in the routing table, ignoring the incoming interface, so it would not drop this traffic. Strict mode fails because the return path differs from the arrival interface under asymmetric routing. This option would be correct if the configuration genuinely used 'reachable-via any'.
Visual reference
Quick reference
Asymmetric Encryption Algorithm Comparison
| Algorithm | Key Exchange | Signatures | Equivalent Security Key | Notes |
|---|---|---|---|---|
| RSA-3072 | Yes | Yes | 128-bit | Widely deployed; slow for bulk data |
| ECDSA P-256 | No | Yes | 128-bit | Fast signatures; standard TLS certs |
| ECDH / ECDHE | Yes | No | 128-bit | Perfect forward secrecy in TLS 1.3 |
| DH / DHE | Yes | No | 128-bit (3072-bit key) | Replaced by ECDHE in modern TLS |
| Ed25519 | No | Yes | ~128-bit | SSH keys, modern PKI |
Go deeper
Related to this question
Learn chapter
ACL-Based Traffic Filtering and Policy-Based Routing
Key term
uRPF
Unicast Reverse Path Forwarding is a network security feature that verifies the source address of incoming packets to prevent IP spoofing attacks.
Key term
MPLS Layer 3 VPN
A technology that uses Multiprotocol Label Switching to create secure, scalable virtual private networks that connect multiple sites at the network layer, where the service provider manages routing between customer sites.
About these practice questions
Courseiva writes every 300-410 question from scratch — 1,401 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.