🔥 40% Off Crucial Exams Memberships — This Week Only

2 days, 10 hours remaining!

ISC2 Systems Security Certified Practitioner (SSCP) Practice Question

Your edge router connects the corporate LAN to two upstream ISPs. During a recent incident, tens of thousands of inbound UDP datagrams arrived with randomly forged source IP addresses, saturating an internal service. Management wants a router-level control that automatically drops any packet whose source address could not legitimately be routed back through the interface on which it arrived. Which configuration best meets this requirement?

  • Deploy a passive network intrusion detection sensor on the router's span port to monitor inbound traffic for malicious signatures.

  • Require IEEE 802.1X authentication on all internal switch access ports before granting network connectivity.

  • Increase the maximum transmission unit (MTU) on the WAN interfaces to prevent fragmentation-based attacks.

  • Enable strict unicast reverse path forwarding (uRPF) on each ISP-facing router interface to perform BCP 38 ingress filtering.

ISC2 Systems Security Certified Practitioner (SSCP)
Network and Communication Security
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot