exam questions

Exam 300-410 All Questions

View all questions & answers for the 300-410 exam

Exam 300-410 topic 1 question 316 discussion

Actual exam question from Cisco's 300-410
Question #: 316
Topic #: 1
[All 300-410 Questions]

First-Hop Security (FHS) is a set of features to optimize IPv6 link operation, and help with scale in large L2 domains. Which of the following are valid First-Hop Security features supported by Cisco? (Choose three.)

  • A. IPv6 RA Guard
  • B. IPv6 Source Guard
  • C. DHCPv6 Guard
  • D. IPv6 Snooping
  • E. DHCPv6 Snooping
Show Suggested Answer Hide Answer
Suggested Answer: ACD 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Muste
Highly Voted 1 year, 9 months ago
Selected Answer: ACD
the question is asking about L2 domains that's why B isn't qualified
upvoted 8 times
Pietjeplukgeluk
1 year ago
The question says that FHS features improve large scale L2 domains. It does eventually just ask IPv6 FHS features, IPv6 Source Guard is actually one of them. Low quality question, but for sore a good one to get you thinking.
upvoted 2 times
...
...
XBfoundX
Most Recent 8 months, 4 weeks ago
Another of those questions..... In this case as Hungarian Dish is saying we need the first FOUR! IPv6 FHS is composed of the following IPv6 security features: IPv6 Snooping, IPv6 Neighbor DiscoveryInspection IPv6 Router Advertisement Guard , IPv6 DHCP Guard, IPv6 Source Guard, IPv6 Prefix Guard, IPv6 Destination Guard. Link based on the manual regarding configs of C9300 switches (brand new) https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9300/software/release/17-13/configuration_guide/sec/b_1713_sec_9300_cg/configuring_ipv6_first_hop_security.pdf
upvoted 3 times
XBfoundX
8 months, 4 weeks ago
IPv6 Snooping IPv6 Neighbor Discovery Inspection IPv6 Router Advertisement Guard IPv6 DHCP Guard IPv6 Source Guard IPv6 Prefix Guard IPv6 Destination Guard
upvoted 3 times
XBfoundX
8 months, 4 weeks ago
Sorry much better like this
upvoted 2 times
...
...
...
[Removed]
10 months, 1 week ago
Selected Answer: ACD
ACD are more suitable i think B is out because IPv6 Source Guard requires IPv6 snooping on Layer 2 anyway. look at question 158
upvoted 1 times
...
Pietjeplukgeluk
10 months, 3 weeks ago
Selected Answer: ABC
A == correct B == correct c == correct d == incorrect Cisco term == "DHCPv6 snooping" https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst_pon/software/configuration_guide/olt_ntw/b-gpon-config-olt-network/m-gpon-olt-nw-dhcpv6-snooping.pdf E. Not correct Can be used in addition to FHS features, but are not adding security on their own(https://networklessons.com/ipv6/ipv6-source-guard) Still i think the FHS requires DHCPv6 or ND inspection to work well, but at their own they do not add security. SO my best guess == A + B + C
upvoted 1 times
bk989
9 months, 1 week ago
There is a such thing as IPv6 snooping as well regarding ND messages
upvoted 1 times
...
...
Horsefeathers
1 year, 3 months ago
Selected Answer: ACD
"IPv6 FHS features enable a better IPv6 link security and management over the layer 2 links. These are the features supported: • IPv6 Snooping • IPv6 Router Advertisement Guard • IPv6 - Destination Guard • Binding Table Recovery • DHCPv6 Guard • IPv6 Source Guard • IPv6 Prefix Guard • Data Gleaning" However: "The configuration of IPv6 Snooping is a prerequisite for IPv6 Source Guard." - therefore skip B https://www.cisco.com/c/en/us/td/docs/routers/7600/ios/15S/configuration/guide/7600_15_0s_book/IPv6_Security.pdf
upvoted 3 times
...
inteldarvid
1 year, 10 months ago
Selected Answer: ACD
A, C, D : Correct: https://www.cisco.com/c/en/us/td/docs/dcn/nx-os/nexus9000/102x/configuration/Security/cisco-nexus-9000-nx-os-security-configuration-guide-102x/m-configuring-ipv6-first-hop-security.html
upvoted 2 times
...
slcc99
1 year, 11 months ago
I think A, B, and C are correct.Because "The IPv6 Snooping Policy feature is deprecated and the Switch Integrated Security Feature (SISF)-based device tracking feature replaces it and offers the same capabilities." https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9300/software/release/17-1/configuration_guide/sec/b_171_sec_9300_cg/configuring_ipv6_first_hop_security.html#:~:text=The%20IPv6%20Snooping%20Policy%20feature%20is%20deprecated%20and%20the%20Switch%20Integrated%20Security%20Feature%20(SISF)%2Dbased%20device%20tracking%20feature%20replaces%20it%20and%20offers%20the%20same%20capabilities.
upvoted 1 times
...
HungarianDish_111
2 years ago
A,B,C,D!!! RA Guard, DHCPv6 Guard, Source Guard, IPv6 ND snooping = device-tracking https://www.ciscolive.com/c/dam/r/ciscolive/us/docs/2019/pdf/BRKSEC-3200.pdf https://networklessons.com/cisco/ccie-routing-switching-written/ipv6-first-hop-security-features https://www.cisco.com/c/en/us/td/docs/routers/7600/ios/15S/configuration/guide/7600_15_0s_book/IPv6_Security.html
upvoted 4 times
Pietjeplukgeluk
1 year, 4 months ago
I agree fully, also https://networklessons.com/ipv6/ipv6-first-hop-security-features adds "Source guard" as a FHS feature.
upvoted 1 times
...
...
Patrick1234
2 years, 4 months ago
Source Guard is also part of the FHS features, however, it needs IPv6 Snooping to be enabled... I would not know why you should not pick that one as well, but i guess it's save to use the given answer here... So A, C, and D seem to be correct.
upvoted 3 times
...
DUBC89x
2 years, 6 months ago
Selected Answer: ACD
Given answer is correct "https://www.cisco.com/c/en/us/td/docs/routers/7600/ios/15S/configuration/guide/7600_15_0s_book/IPv6_Security.html"
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...