exam questions

Exam 300-410 All Questions

View all questions & answers for the 300-410 exam

Exam 300-410 topic 1 question 141 discussion

Actual exam question from Cisco's 300-410
Question #: 141
Topic #: 1
[All 300-410 Questions]

Which configuration feature should be used to block rogue router advertisements instead of using the IPv6 Router Advertisement Guard feature?

  • A. VACL blocking broadcast frames from nonauthorized hosts
  • B. PVLANs with promiscuous ports associated to route advertisements and isolated ports for nodes
  • C. PVLANs with community ports associated to route advertisements and isolated ports for nodes
  • D. IPv4 ACL blocking route advertisements from nonauthorized hosts
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Dirkd0344
Highly Voted 3 years, 4 months ago
The answer is not D, as this is regarding IPv6. The answer would be B. You would configure the switch with PVLANs, configure the switchport where you would expect to see RAs as a promiscuous port, and configure the client ports as isolated ports. With this configuration if any rogue RAs came in on an isolated port it would not be able to offer SLAAC addresses to any other client on the other isolated ports.
upvoted 16 times
dapardo
1 year ago
Nice explanation
upvoted 1 times
...
baid
3 years, 2 months ago
Thanks for your explanation. It's right.
upvoted 2 times
...
...
AonDuine
Most Recent 8 months, 2 weeks ago
Based on Chatgpt the correct answer is C. Although none of the options directly match the functionality of IPv6 Router Advertisement Guard, using PVLANs with community ports and isolated ports can help isolate traffic and control communication, making it more difficult for rogue RAs to reach unauthorized nodes. This setup is an indirect but potential method of mitigating rogue RAs without using RA Guard.
upvoted 1 times
...
[Removed]
9 months, 4 weeks ago
Selected Answer: B
B is correct
upvoted 1 times
...
kldoyle97
10 months, 3 weeks ago
Selected Answer: B
Private VLANs can be used a security feature to partition ports into separate broadcast domains. Configure the port that will be receiving router advertisements as promiscuous because promiscuous ports can communicate with community and isolated private VLANS. If you configured the port that receives router advertisements in a community private VLAN, it wouldn't be able to forward traffic to isolated ports, only to other ports in its community VLAN
upvoted 4 times
...
chris110
1 year, 8 months ago
Selected Answer: B
To block rogue router advertisements in an IPv6 network, you should use option B: B. PVLANs (Private VLANs) with promiscuous ports associated with route advertisements and isolated ports for nodes. Private VLANs help in segmenting traffic within a VLAN and provide isolation between devices within the same VLAN. In this context, you can configure a PVLAN such that the promiscuous port (connected to a trusted router) is allowed to send router advertisements, while the isolated ports (connected to end-user devices) are not allowed to send such advertisements. This way, you can prevent rogue router advertisements from unauthorized sources within the same VLAN.
upvoted 4 times
...
inteldarvid
1 year, 10 months ago
Selected Answer: B
B option: https://www.exam-answer.com/which-configuration-feature-blocks-rogue-router-advertisements-ipv6
upvoted 2 times
...
HungarianDish_111
1 year, 11 months ago
Selected Answer: B
https://www.ciscolive.com/c/dam/r/ciscolive/emea/docs/2020/pdf/BRKSEC-3200.pdf Mitigating Rogue RA: Host Isolation Private VLANs (PVLAN) where nodes (isolated port) can only contact the official router (promiscuous port)
upvoted 3 times
...
[Removed]
2 years, 9 months ago
Ref: Advanced IPv6 Security Threats and Mitigation – Cisco “LAN Security with First Hop Security (FHS) … Mitigating Rogue RA: Host Isolation Prevent Node-Node Layer-2 communication by using: • Private VLANs (PVLAN) where nodes (isolated port) can only contact the official router (promiscuous port) …” A. VACL blocking broadcast frames from nonauthorized hosts Wrong answer. B. PVLANs with promiscuous ports associated to route advertisements and isolated ports for nodes Correct answer. C. PVLANs with community ports associated to route advertisements and isolated ports for nodes Wrong answer. D. IPv4 ACL blocking route advertisements from nonauthorized hosts Wrong answer.
upvoted 2 times
_PrettyStupid_
2 years, 6 months ago
Agreed with GreatDane, checked the session video from cisco live (min 09:25 to 11:40 aprox) https://www.youtube.com/watch?v=RCxC2gIV4jo
upvoted 1 times
...
...
kellyDD
2 years, 10 months ago
promiscuous ports and isolated ports can communicate, right?
upvoted 1 times
...
thanh123
3 years ago
Selected Answer: B
Techincally, you can use VACL to block RA but there are some issues. I haven't tested because GNS3 won't support VACL or private VLAN, I even don't have physical hardware, either. So correct me if I'm wrong: 1. You can use ACL to filter IP or MAC of rouge host generates RA. Downside of this is that if rouge router change IP or MAC, you have to change the ACL as well, which is not scale very well 2. If we choose to filter based on Layer 2 destination MAC, which is multicast , IPV6 do not have broadcast. Then there is a chance that you accidentally block legitimate router RA ,because there is no difference between rouge router and legitimate router that generate RA. With private VLAN , you just add rouge router on isolated port , legitimate router with promiscuous port , everything will automatically work
upvoted 1 times
...
bayolo10
3 years, 1 month ago
Answer should A,https://www.geeksforgeeks.org/vlan-acl-vacl/
upvoted 2 times
pompedom
2 years, 11 months ago
It's A because PVlan limits the ability for isolated ports to communicate with other isolated ports at all, not only route advertisements.
upvoted 1 times
...
...
wts
3 years, 1 month ago
Selected Answer: D
Certain switch platforms can already implement some level of rogue RA filtering by the administrator configuring Access Control Lists (ACLs) that block RA ICMP messages that might be inbound on "user" ports. https://datatracker.ietf.org/doc/html/rfc6104#section-3.3
upvoted 1 times
...
steiger
3 years, 5 months ago
The answer should be D
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago