350-401 exam dumps

350-401 practice question 574 of 631

Implementing Cisco Enterprise Network Core Technologies. Professional level, Cisco. Free question with the correct answer and a full explanation.

350-401 Question 574

Select 4

An enterprise network administrator is tasked with securing an IPv6-enabled network against threats such as rogue routers, spoofed DHCP servers, and Neighbor Discovery Protocol (NDP) attacks. The network is configured with multiple IPv6 subnets, and the administrator wants to implement security features at the Layer 2 level to prevent these threats. Which combination of IPv6 First Hop Security (FHS) features should the administrator implement?

  1. A

    RA Guard

  2. B

    DHCPv6 Guard

  3. C

    Binding Table

  4. D

    ND Inspection/Snooping

  5. E

    IPv6 Source Guard

Show answer and explanation

Correct answers: A, B, D, E

Explanation

IPv6 First Hop Security (FHS) features, such as RA Guard, DHCPv6 Guard, ND Inspection, and IPv6 Source Guard, are designed to protect an IPv6-enabled network from common Layer 2-based threats. RA Guard secures the network from rogue RAs, DHCPv6 Guard prevents unauthorized DHCP servers, ND Inspection ensures the integrity of NDP messages, and IPv6 Source Guard blocks traffic from spoofed IPv6 addresses. While the Binding Table is essential to the functionality of some of these features, it is not configured as a standalone security feature.

  • A. Correct.

    RA Guard prevents rogue Router Advertisements (RA) by allowing only legitimate RAs from authorized devices. This is necessary to secure the network from rogue routers and is part of IPv6 First Hop Security (FHS).

  • B. Correct.

    DHCPv6 Guard ensures that only authorized DHCPv6 servers can provide addressing information and prevents spoofed DHCP messages. This feature is critical for protecting the integrity of the DHCP process in IPv6 networks.

  • C. Incorrect.

    The Binding Table is used internally by other FHS features (e.g., ND Inspection and IPv6 Source Guard) but is not a standalone FHS feature. It is not directly configured but rather dynamically built by the system.

  • D. Correct.

    ND Inspection/Snooping mitigates NDP-based attacks by validating NDP messages (e.g., NS and NA messages) against the binding table. It ensures that IPv6 neighbors are legitimate according to the network's rules.

  • E. Correct.

    IPv6 Source Guard blocks traffic from devices with spoofed IPv6 addresses by validating source addresses against the binding table. This prevents malicious activities such as address spoofing.

Timed practice exam

Take a 350-401 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam