300-410 exam dumps

300-410 practice question 234 of 293

Implementing Cisco Enterprise Advanced Routing and Services. Professional level, Cisco. Free question with the correct answer and a full explanation.

300-410 Question 234

Select 4

A network administrator is tasked with securing an IPv6-enabled network from malicious activities such as rogue router advertisements, spoofed DHCPv6 servers, and neighbor discovery spoofing attacks. Which combination of IPv6 First Hop Security (FHS) features should the administrator enable on the network switches to mitigate these threats?

  1. A

    RA Guard

  2. B

    DHCP Guard

  3. C

    IPv6 Source Guard

  4. D

    ND Inspection/Snooping

  5. E

    Port Security

Show answer and explanation

Correct answers: A, B, C, D

Explanation

To secure an IPv6-enabled network, the administrator should implement a combination of IPv6 First Hop Security features, including RA Guard to block rogue router advertisements, DHCP Guard to filter unauthorized DHCPv6 server messages, IPv6 Source Guard to prevent source address spoofing, and ND Inspection/Snooping to protect against NDP-based attacks. Port Security, while useful for controlling MAC address assignments, is not specific to IPv6 First Hop Security threats.

  • A. Correct.

    RA Guard prevents unauthorized or rogue router advertisements on the network, which can redirect traffic through malicious devices.

  • B. Correct.

    DHCP Guard protects the network by filtering and blocking unauthorized DHCPv6 server messages, preventing attackers from providing malicious IP configuration.

  • C. Correct.

    IPv6 Source Guard validates the source IP address of a packet against a binding table to prevent spoofing or impersonation attacks.

  • D. Correct.

    ND Inspection/Snooping verifies the integrity of Neighbor Discovery Protocol (NDP) messages and protects against NDP-based attacks like neighbor spoofing.

  • E. Incorrect.

    Port Security is primarily used for MAC address-based control on switch ports and does not address IPv6-specific threats related to rogue RAs, DHCPv6 spoofing, or NDP attacks.

Timed practice exam

Take a 300-410 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam