Courseiva
hardMultiple ChoiceObjective-mapped

300-410 Practice Question: An engineer configures unicast Reverse Path…

An engineer configures unicast Reverse Path Forwarding (uRPF) in strict mode on an interface. After the configuration, legitimate traffic from a customer network is being dropped. The engineer confirms that the route for the customer subnet exists in the routing table and points to the correct interface. What is the most likely explanation?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Asymmetric routing is in use, and the return route for the source IP points to a different interface.

Strict uRPF checks that the source IP address of an incoming packet has a route in the routing table that points back to the same interface. If the customer network uses asymmetric routing (i.e., traffic comes in one interface but the return route points out a different interface), strict uRPF will drop the traffic. The edge case is that even if the route exists, if it does not point to the incoming interface, the packet is dropped.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Asymmetric routing is in use, and the return route for the source IP points to a different interface.

    Why this is correct

    Strict uRPF requires that the best route to the source IP address points back to the same interface on which the packet was received. If asymmetric routing is present, the return path may be via a different interface, causing strict uRPF to drop the packet.

  • The 'allow-default' option is not enabled, so default routes are not considered.

    Why it's wrong here

    The 'allow-default' option is used in loose mode to allow packets with source IPs that match a default route. In strict mode, default routes are not used for the check unless explicitly configured, but the question states the route exists, so this is not the issue.

  • The 'ip verify unicast source reachable-via any' command was used instead of 'rx'

    Why it's wrong here

    Using 'any' enables loose mode, not strict mode. The question states strict mode is configured, so this is not the case.

  • The customer subnet is a summary route, and the more specific route is missing.

    Why it's wrong here

    uRPF uses the best route in the routing table; if a summary route exists, it is used for the check. Missing more specific routes would not cause drops if the summary is present.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

Quick reference

Asymmetric Encryption Algorithm Comparison

AlgorithmKey ExchangeSignaturesEquivalent Security KeyNotes
RSA-3072YesYes128-bitWidely deployed; slow for bulk data
ECDSA P-256NoYes128-bitFast signatures; standard TLS certs
ECDH / ECDHEYesNo128-bitPerfect forward secrecy in TLS 1.3
DH / DHEYesNo128-bit (3072-bit key)Replaced by ECDHE in modern TLS
Ed25519NoYes~128-bitSSH keys, modern PKI

About these practice questions

This 300-410 question is part of Courseiva's 1,966-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.