First-Hop Security (FHS) is a set of features to optimize IPv6 link operation, and help with scale in large L2 domains. Which of the following are valid First-Hop Security features supported by Cisco? (Choose three.)
The question says that FHS features improve large scale L2 domains. It does eventually just ask IPv6 FHS features, IPv6 Source Guard is actually one of them. Low quality question, but for sore a good one to get you thinking.
Another of those questions.....
In this case as Hungarian Dish is saying we need the first FOUR!
IPv6 FHS is composed of the following IPv6 security features: IPv6 Snooping, IPv6
Neighbor DiscoveryInspection
IPv6 Router Advertisement Guard ,
IPv6 DHCP Guard,
IPv6 Source Guard,
IPv6 Prefix Guard,
IPv6 Destination Guard.
Link based on the manual regarding configs of C9300 switches (brand new)
https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9300/software/release/17-13/configuration_guide/sec/b_1713_sec_9300_cg/configuring_ipv6_first_hop_security.pdf
A == correct
B == correct
c == correct
d == incorrect Cisco term == "DHCPv6 snooping" https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst_pon/software/configuration_guide/olt_ntw/b-gpon-config-olt-network/m-gpon-olt-nw-dhcpv6-snooping.pdf
E. Not correct Can be used in addition to FHS features, but are not adding security on their own(https://networklessons.com/ipv6/ipv6-source-guard)
Still i think the FHS requires DHCPv6 or ND inspection to work well, but at their own they do not add security. SO my best guess == A + B + C
"IPv6 FHS features enable a better IPv6 link security and management over the layer 2 links.
These are the features supported:
• IPv6 Snooping
• IPv6 Router Advertisement Guard
• IPv6 - Destination Guard
• Binding Table Recovery
• DHCPv6 Guard
• IPv6 Source Guard
• IPv6 Prefix Guard
• Data Gleaning"
However:
"The configuration of IPv6 Snooping is a prerequisite for IPv6 Source Guard." - therefore skip B
https://www.cisco.com/c/en/us/td/docs/routers/7600/ios/15S/configuration/guide/7600_15_0s_book/IPv6_Security.pdf
A, C, D : Correct:
https://www.cisco.com/c/en/us/td/docs/dcn/nx-os/nexus9000/102x/configuration/Security/cisco-nexus-9000-nx-os-security-configuration-guide-102x/m-configuring-ipv6-first-hop-security.html
I think A, B, and C are correct.Because "The IPv6 Snooping Policy feature is deprecated and the Switch Integrated Security Feature (SISF)-based device tracking feature replaces it and offers the same capabilities."
https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9300/software/release/17-1/configuration_guide/sec/b_171_sec_9300_cg/configuring_ipv6_first_hop_security.html#:~:text=The%20IPv6%20Snooping%20Policy%20feature%20is%20deprecated%20and%20the%20Switch%20Integrated%20Security%20Feature%20(SISF)%2Dbased%20device%20tracking%20feature%20replaces%20it%20and%20offers%20the%20same%20capabilities.
Source Guard is also part of the FHS features, however, it needs IPv6 Snooping to be enabled... I would not know why you should not pick that one as well, but i guess it's save to use the given answer here... So A, C, and D seem to be correct.
Given answer is correct
"https://www.cisco.com/c/en/us/td/docs/routers/7600/ios/15S/configuration/guide/7600_15_0s_book/IPv6_Security.html"
upvoted 2 times
...
This section is not available anymore. Please use the main Exam Page.300-410 Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Muste
Highly Voted 1 year, 9 months agoPietjeplukgeluk
1 year agoXBfoundX
Most Recent 8 months, 4 weeks agoXBfoundX
8 months, 4 weeks agoXBfoundX
8 months, 4 weeks ago[Removed]
10 months, 1 week agoPietjeplukgeluk
10 months, 3 weeks agobk989
9 months, 1 week agoHorsefeathers
1 year, 3 months agointeldarvid
1 year, 10 months agoslcc99
1 year, 11 months agoHungarianDish_111
2 years agoPietjeplukgeluk
1 year, 4 months agoPatrick1234
2 years, 4 months agoDUBC89x
2 years, 6 months ago