Ingress filtering
Filtering of traffic entering a network, commonly used at the edge to drop packets whose source addresses cannot legitimately arrive from that direction (anti-spoofing).
Ingress filtering is the filtering of traffic as it enters a network. NIST SP 800-41 Rev 1 defines it in that general sense. The form most associated with the term is anti-spoofing: at the network edge, a router or firewall drops inbound packets whose source addresses could not legitimately arrive from that direction, such as addresses belonging to the internal network, private IP addresses arriving from the internet, or unallocated ranges. RFC 2827, published as BCP 38, describes the provider-side version, in which a network accepts from each customer only the source addresses assigned to that customer.
Its counterpart is egress filtering, which limits what may leave. The two work together: egress filtering that permits only your own source addresses helps stop your network being used to spoof others, while ingress filtering rejects forged traffic arriving at yours. Anti-spoofing filtering matters most against attacks that depend on forged sources, such as reflection attacks and the smurf attack.
Exam relevance: a scenario is likely to describe packets from outside that claim an internal source address, or to ask which control limits spoofed traffic at the edge. Candidates are expected to keep direction straight: ingress is what enters, egress is what leaves.