IPv6 questions test address types (global unicast, link-local, multicast, anycast), address assignment (SLAAC, DHCPv6, EUI-64), OSPFv3, and dual-stack. The CCNA often presents an IPv6 address and asks you to identify the prefix, type, or calculate the EUI-64 interface ID.
Start Scenario PracticeA network engineer is configuring IPv6 First Hop Security on a Cisco switch to mitigate rogue RA attacks. The engineer enables RA guard on the switch and applies a policy that allows only the default gateway to send RAs. After configuration, hosts are unable to obtain IPv6 addresses via SLAAC. The engineer checks the switch and sees that RA guard is dropping all RAs. What is the most likely cause?
Explanation: RA Guard drops Router Advertisements (RAs) based on a policy that defines which devices are authorized to send them. If the policy does not include the IPv6 address or MAC address of the legitimate default gateway, the switch will treat all RAs as unauthorized and drop them, preventing hosts from performing SLAAC. This is the most likely cause because the engineer enabled RA guard with a policy but failed to specify the trusted gateway's identity.
Consider the following IPv6 access-list on a Cisco IOS-XE router: ``` ipv6 access-list PERMIT_ICMP permit icmp any any echo-request permit icmp any any echo-reply deny ipv6 any any ! interface GigabitEthernet0/0 ipv6 traffic-filter PERMIT_ICMP in ``` What is the effect of this configuration?
Explanation: The ACL explicitly permits only ICMPv6 echo-request and echo-reply messages, which are the packets used by IPv6 ping. The final 'deny ipv6 any any' statement drops all other IPv6 traffic. Since the ACL is applied inbound on GigabitEthernet0/0 via the 'ipv6 traffic-filter' command, only IPv6 ping is allowed in; all other IPv6 packets are denied.
Drag and drop the steps of stateless DHCPv6 address assignment steps into the correct order, from first to last.
Explanation: Stateless DHCPv6 uses SLAAC for addressing and DHCPv6 for additional parameters. The host sends an RS, receives an RA with the O flag, then sends an Information-Request and receives a Reply with options like DNS.
Drag and drop the steps of NAT64 IPv6-to-IPv4 translation flow into the correct order, from first to last.
Explanation: NAT64 translates IPv6 packets to IPv4. The IPv6 host sends a packet to a synthetic IPv6 address, the router extracts the embedded IPv4 destination, creates a NAT64 binding, translates headers, and forwards the IPv4 packet.
Examine the following configuration: interface GigabitEthernet0/0 ip address 172.16.1.1 255.255.255.0 ipv6 address 2001:db8:1::1/64 ipv6 ospf 100 area 0 ! What is missing from this configuration to enable OSPFv3 on this interface?
Explanation: OSPFv3 requires an active OSPFv3 process on the router before it can be enabled on any interface. The 'ipv6 router ospf 100' global command creates the OSPFv3 process with process ID 100, which is necessary for the interface-level 'ipv6 ospf 100 area 0' command to function. Without this global process, the interface configuration is incomplete and OSPFv3 will not operate.
IPv6 questions test address types (global unicast, link-local, multicast, anycast), address assignment (SLAAC, DHCPv6, EUI-64), OSPFv3, and dual-stack. The CCNA often presents an IPv6 address and asks you to identify the prefix, type, or calculate the EUI-64 interface ID. These appear throughout the 350-401 and require you to apply your knowledge, not just recall facts.
Cisco doesn't publish an exact breakdown, but scenario-based questions (especially exhibit and command-output formats) make up a significant portion of the 350-401. Practicing each scenario type ensures you're ready for any format.
Yes. Courseiva provides free 350-401 scenario practice across all official exam domains. The platform includes scenario-based questions, command-output interpretation, topic-based practice, mock exams, and readiness tracking — no account required.
Launch a full IPv6 Configuration Scenarios session with instant scoring and detailed explanations.
Start Scenario Practice →