exam questions

Exam 300-410 All Questions

View all questions & answers for the 300-410 exam

Exam 300-410 topic 1 question 253 discussion

Actual exam question from Cisco's 300-410
Question #: 253
Topic #: 1
[All 300-410 Questions]

What is a function of IPv6 Source Guard?

  • A. It inspects ND and DHCP packets to build an address binding table.
  • B. It works with address glean or ND to find existing addresses.
  • C. It notifies the ND protocol to inform hosts if the traffic is denied by it.
  • D. It denies traffic from known sources and allocated addresses.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
NoUserName1234
Highly Voted 2 years, 6 months ago
Selected Answer: B
https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/ipv6_fhsec/configuration/xe-3s/ip6f-xe-3s-book/ip6-src-guard.html
upvoted 7 times
JKStinn
2 years, 4 months ago
IPv6 source guard does not inspect ND or DHCP packets; rather, it works in conjunction with IPv6 neighbor discovery (ND) inspection or IPv6 address glean, both of which detect existing addresses on the link and store them into the binding table.
upvoted 4 times
Hermin
2 years, 1 month ago
Source Guard only looks at information found in the binding table, and it doesn’t fill the binding table. You need another feature like ND inspection or IPv6 snooping to do this. https://networklessons.com/cisco/ccie-routing-switching-written/ipv6-source-guard
upvoted 3 times
...
...
...
Brahim90
Most Recent 2 months ago
Selected Answer: B
Given answer is correct per cisco book page 931. IPv6 Source Guard can block it and drop it. For traffic to be from a known source and allowed, the source must be in the binding table. The source is either learned using ND inspection or IPv6 address gleaning and therefore relies on IPv6 snooping being configured first on Layer 2 access or trunk ports and VLANs.
upvoted 1 times
...
[Removed]
9 months, 1 week ago
Selected Answer: B
B is correct IPv6 source guard does not inspect ND or DHCP packets; rather, it works in conjunction with IPv6 neighbor discovery (ND) inspection or IPv6 address glean, both of which detect existing addresses on the link and store them into the binding table. https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/ipv6_fhsec/configuration/xe-3s/ip6f-xe-3s-book/ip6-src-guard.html#:~:text=IPv6%20source%20guard%20does%20not%20inspect%20ND%20or%20DHCP%20packets%3B%20rather%2C%20it%20works%20in%20conjunction%20with%20IPv6%20neighbor%20discovery%20(ND)%20inspection%20or%20IPv6%20address%20glean%2C%20both%20of%20which%20detect%20existing%20addresses%20on%20the%20link%20and%20store%20them%20into%20the%20binding%20table.
upvoted 1 times
...
steficris89898
1 year, 1 month ago
IPv6 source guard is an interface feature between the populated binding table and data traffic filtering. This feature enables the device to deny traffic when it is originated from an address that is not stored in the binding table. IPv6 source guard does not inspect ND or DHCP packets; rather, it works in conjunction with IPv6 neighbor discovery (ND) inspection or IPv6 address glean, both of which detect existing addresses on the link and store them into the binding table. IPv6 source guard is an interface between the populated binding table and data traffic filtering, and the binding table must be populated with IPv6 prefixes for IPv6 source guard to work.
upvoted 1 times
...
inteldarvid
1 year, 9 months ago
Selected Answer: B
very sorry team, with my question before, the option correct is ""B"", look this info: https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/ipv6_fhsec/configuration/xe-16/ip6f-xe-16-book/ip6-src-guard.pdf
upvoted 2 times
...
inteldarvid
1 year, 9 months ago
Selected Answer: D
team is option D: IPv6 source guard can deny traffic from unknown sources or unallocated addresses, such as traffic from sources not assigned by a DHCP server. When traffic is denied, the IPv6 address glean feature is notified so that it can try to recover the traffic by querying the DHCP server or by using IPv6 ND https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/ipv6_fhsec/configuration/15-e/ip6f-15-e-book/ip6f-15-e-book_chapter_0110.pdf
upvoted 1 times
...
jarz
2 years, 6 months ago
Selected Answer: A
An entry is installed in the binding table when one of the following conditions is satisfied: • An IPv6 binding is learnt through DHCP. • An IPv6 address or prefix is learnt through NDP. • A static binding is configured by the user. Source https://www.cisco.com/c/en/us/td/docs/routers/7600/ios/15S/configuration/guide/7600_15_0s_book/IPv6_Security.pdf
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago