350-501 · Question #64
Refer to the exhibit. R1 is connected to two service providers and is under a DDoS attack. Which statement about this design is true if uRPF in strict mode is configured on both interfaces?
The correct answer is D. R1 drops all traffic that ingresses either interface that has a FIB entry that exits a different. Unicast Reverse Path Forwarding (uRPF) in strict mode works by checking the FIB (Forwarding Information Base): when a packet arrives on an interface, the router looks up the source IP address in the FIB and checks whether the best return path for that source exits through the sam
Question
Refer to the exhibit. R1 is connected to two service providers and is under a DDoS attack. Which statement about this design is true if uRPF in strict mode is configured on both interfaces?
Exhibit
Options
- AR1 accepts source addresses on interface gigabitethernet0/1 that are private addresses
- BR1 permits asymmetric routing as long as the AS-RATH attribute entry matches the connected
- CR1 drops destination addresses that are routed to a null interface on the router
- DR1 drops all traffic that ingresses either interface that has a FIB entry that exits a different
How the community answered
(33 responses)- A3% (1)
- B3% (1)
- C6% (2)
- D88% (29)
Explanation
Unicast Reverse Path Forwarding (uRPF) in strict mode works by checking the FIB (Forwarding Information Base): when a packet arrives on an interface, the router looks up the source IP address in the FIB and checks whether the best return path for that source exits through the same interface the packet arrived on. If the FIB entry for the source address points to a different interface, the packet is dropped. This prevents IP spoofing but does not support asymmetric routing. In a DDoS scenario with two ISP uplinks, strict mode drops any traffic whose source address has a FIB return path out a different interface than where it ingressed.
Topics
Community Discussion
No community discussion yet for this question.
