350-401 Question 571
Single answerA network administrator is troubleshooting an issue in an IPv6-enabled network where rogue Router Advertisements (RAs) from an unauthorized device are causing connectivity problems. Which IPv6 First Hop security feature should the administrator configure on the access layer switches to prevent this issue?
- A
RA Guard
- B
DHCP Guard
- C
ND Inspection/Snooping
- D
Source Guard
Show answer and explanation
Correct answer: A
Explanation
RA Guard is an IPv6 First Hop security feature that filters and blocks unauthorized Router Advertisements (RAs) on the network. This feature is particularly useful in preventing rogue devices from disrupting the network by sending illegitimate RAs. In contrast, other features like DHCP Guard, ND Inspection, and Source Guard address different types of threats and are not suited for mitigating RA-related issues.
- A. Correct.
RA Guard is specifically designed to mitigate threats caused by rogue or unauthorized Router Advertisements (RAs) in an IPv6 network. By applying RA Guard on the access layer switches, the administrator can filter out unauthorized RAs and prevent disruption.
- B. Incorrect.
DHCP Guard is used to prevent rogue DHCP servers from providing IP addresses or configuration to client devices. It is not designed to address issues with rogue Router Advertisements.
- C. Incorrect.
ND Inspection/Snooping helps protect against Neighbor Discovery (ND)-based attacks, such as spoofing or man-in-the-middle attacks. However, it does not mitigate issues caused by rogue RAs.
- D. Incorrect.
Source Guard is used to prevent IP or MAC spoofing attacks by verifying the source IP address and its binding. It is not relevant for managing rogue Router Advertisements.