Courseiva
Knowledge + Practice
CertificationsVendorsCareer RoadmapsLabs & ToolsStudy GuidesGlossaryPractice Questions
C
Courseiva

Free IT certification practice questions with explained answers for CCNA, CompTIA, AWS, Azure, Google Cloud, and more.

Certification Practice Questions

CCNA practice questionsSecurity+ SY0-701 practice questionsAWS SAA-C03 practice questionsAZ-104 practice questionsAZ-900 practice questionsCLF-C02 practice questionsA+ Core 1 practice questionsGoogle Cloud ACE practice questionsCySA+ CS0-003 practice questionsNetwork+ N10-009 practice questions
View all certifications →

Product

CertificationsCertification PathsExam TopicsPractice TestsExam Dumps vs Practice TestsStudy HubComparisons

Company

AboutContactEditorial PolicyQuestion Writing PolicyTrust Center

Legal

Privacy PolicyTerms of Service

Courseiva is a free IT certification practice platform offering original exam-style practice questions, detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics for Cisco, CompTIA, Microsoft, AWS, and other technology certifications.

© 2026 Courseiva. Courseiva is operated by JTNetSolutions Ltd. All rights reserved.

Courseiva is an independent certification practice platform and is not affiliated with, endorsed by, or sponsored by Cisco, Microsoft, AWS, CompTIA, Google, ISC2, ISACA, or any other certification vendor. Vendor names and certification marks are used only to identify the exams learners are preparing for.

Certifications›300-410›Objectives›IPv6 First Hop Security
Objective 305.0

IPv6 First Hop Security

300-410 Practice Questions

Full Practice Test →All Objectives

300-410 IPv6 First Hop Security — Practice Questions

30 questions from this objective

Question 2mediummultiple choice
Open the full VLAN trunking answer →

A network engineer is troubleshooting an IPv6 neighbor discovery issue on a switch running IOS-XE. Hosts on VLAN 100 are intermittently losing connectivity to the default gateway. The switch is configured with IPv6 First Hop Security features including RA Guard and DHCPv6 Guard. The engineer notices that the switch is dropping valid Router Advertisements from the legitimate router. What is the most likely cause of this issue?

Question 3hardmultiple choice
Read the full DHCP explanation →

An engineer is troubleshooting a network where IPv6 hosts cannot obtain IP addresses via DHCPv6. The switch is configured with DHCPv6 Guard to prevent rogue DHCP servers. The legitimate DHCPv6 server is connected to port GigabitEthernet1/0/1. The engineer sees that DHCPv6 Solicit messages from hosts reach the server, but the server's Advertise and Reply messages are not reaching the hosts. What is the most likely root cause?

Question 4mediummultiple choice
Study the full IPv6 explanation →

A network engineer is troubleshooting an issue where IPv6 traffic is being forwarded incorrectly on a switch. The switch is configured with IPv6 Source Guard on access ports. A legitimate host on port Fa0/1 with IPv6 address 2001:db8:1::10 is unable to send traffic to the default gateway. The engineer checks the IPv6 binding table and sees that the host's entry is missing. What is the most likely cause?

Question 5hardmultiple choice
Open the full VLAN trunking answer →

An engineer is troubleshooting an IPv6 connectivity issue where hosts on VLAN 10 cannot reach the internet. The switch is configured with IPv6 First Hop Security features including RA Guard and DHCPv6 Guard. The legitimate router is connected to port Gi1/0/1. The engineer notices that the router is sending RAs, but hosts are not receiving them. The switch shows that RA Guard is dropping packets on port Gi1/0/1. What is the most likely misconfiguration?

Question 6hardmultiple choice
Study the full IPv6 explanation →

A network engineer is troubleshooting an issue where IPv6 hosts are unable to perform Duplicate Address Detection (DAD) successfully. The switch is configured with IPv6 First Hop Security features including ND Inspection and ND Suppress. The engineer notices that Neighbor Solicitation messages for DAD are being dropped by the switch. What is the most likely cause?

Question 7mediummultiple choice
Open the full VLAN trunking answer →

An engineer is troubleshooting a network where IPv6 hosts on VLAN 20 are unable to communicate with each other. The switch is configured with IPv6 First Hop Security features including Private VLAN (PVLAN) and IPv6 Source Guard. The hosts are in the same VLAN but cannot ping each other. What is the most likely cause?

Question 8mediummultiple choice
Study the full IPv6 explanation →

A network engineer is troubleshooting an issue where IPv6 traffic from a host is being dropped by the switch. The switch has IPv6 Source Guard enabled. The host has a static IPv6 address 2001:db8:2::20. The engineer sees that the binding table does not contain an entry for this host. What should the engineer do to resolve the issue without disabling IPv6 Source Guard?

Question 9hardmultiple choice
Study the full IPv6 explanation →

An engineer is troubleshooting an issue where a rogue IPv6 router is sending false Router Advertisements on the network, causing hosts to use a malicious default gateway. The switch is configured with IPv6 First Hop Security features. The engineer wants to prevent this attack while allowing the legitimate router to send RAs. What is the correct configuration approach?

Question 10mediummultiple choice
Study the full IPv6 explanation →

A network engineer is troubleshooting an issue where IPv6 hosts are receiving multiple Router Advertisements from different routers, causing routing instability. The switch is configured with IPv6 First Hop Security features. The engineer wants to ensure that only the primary router's RAs are accepted by hosts. What is the most effective solution?

Question 11mediummultiple choice
Study the full IPv6 explanation →

A network engineer runs the following command on Router R1:

R1# show ipv6 snooping policy
Interface                      Policy                      Role            State

Gi0/0/0 GUARD_POLICY device-guard ACTIVE Gi0/0/1 GUARD_POLICY device-guard ACTIVE Gi0/0/2 (default) host ACTIVE

Based on this output, which statement is correct?

Question 12mediummultiple choice
Study the full IPv6 explanation →

A network engineer runs the following command on Router R1:

R1# show ipv6 nd raguard policy
Interface                      Policy                      Role            State

Gi0/0/0 RA_GUARD router ACTIVE Gi0/0/1 RA_GUARD host ACTIVE Gi0/0/2 (default) host ACTIVE

Based on this output, which statement is correct?

Question 13mediummultiple choice
Read the full DHCP explanation →

A network engineer runs the following command on Router R1:

R1# show ipv6 dhcp guard policy
Interface                      Policy                      Role            State

Gi0/0/0 DHCP_GUARD server ACTIVE Gi0/0/1 DHCP_GUARD client ACTIVE Gi0/0/2 (default) client ACTIVE

Based on this output, which statement is correct?

Question 14mediummultiple choice
Study the full IPv6 explanation →

A network engineer runs the following command on Router R1:

R1# show ipv6 source-guard policy
Interface                      Policy                      Role            State

Gi0/0/0 SRC_GUARD host ACTIVE Gi0/0/1 SRC_GUARD host ACTIVE Gi0/0/2 (default) host ACTIVE

Based on this output, which statement is correct?

Question 15mediummultiple choice
Study the full IPv6 explanation →

A network engineer runs the following command on Router R1:

R1# show ipv6 neighbors

IPv6 Address Age Link-layer Addr State Interface 2001:DB8:1::1 0 aaaa.bbbb.cccc REACH Gi0/0/0 2001:DB8:1::2 10 aaaa.bbbb.cccd STALE Gi0/0/0 2001:DB8:1::3 - aaaa.bbbb.ccce DELAY Gi0/0/1 FE80::1 0 aaaa.bbbb.cccf REACH Gi0/0/0

Based on this output, which statement is correct?

Question 16mediummultiple choice
Read the full DHCP explanation →

A network engineer runs the following command on Router R1:

R1# show ipv6 dhcp binding

Client: FE80::1 DUID: 0003000100AABBCCDDEE

Username: unknown

IA NA: IA ID 0x00010001, T1 302400, T2 483840 Address: 2001:DB8:1::100/128 Preferred lifetime 604800, valid lifetime 2592000 Expires at Sep 15 2024 12:00 PM (2592000 seconds)

Based on this output, which statement is correct?

Question 17mediummultiple choice
Read the full DHCP explanation →

A network engineer runs the following command on Router R1:

R1# show ipv6 dhcp interface Gi0/0/0

Gi0/0/0 is in server mode Uses prefix 2001:DB8:1::/64 Rapid-Commit is disabled Preference value: 0 Information refresh option: 86400 DNS server: 2001:DB8::1 Domain name: example.com Active clients: 5 Pool: DHCP_POOL

Based on this output, which statement is correct?

Question 18mediummultiple choice
Study the full IPv6 explanation →

A network engineer runs the following command on Router R1:

R1# show ipv6 traffic

IPv6 statistics: Rcvd: 1000 total, 800 unicast, 200 multicast Sent: 900 total, 700 unicast, 200 multicast Errors: 0 Dropped: 0 ND statistics: NS: 50 received, 40 sent NA: 30 received, 20 sent RS: 10 received, 5 sent RA: 2 received, 8 sent Redirect: 0 received, 0 sent

Based on this output, which statement is correct?

Question 19mediummultiple choice
Open the full VLAN trunking answer →

A network engineer runs the following command on Router R1:

R1# show ipv6 snooping binding

IPv6 Address MAC Address VLAN Interface State 2001:DB8:1::100 aaaa.bbbb.cccc 10 Gi0/0/0 ACTIVE 2001:DB8:1::101 aaaa.bbbb.cccd 10 Gi0/0/0 ACTIVE 2001:DB8:1::102 aaaa.bbbb.ccce 10 Gi0/0/1 ACTIVE 2001:DB8:1::103 aaaa.bbbb.cccf 10 Gi0/0/1 ACTIVE

Based on this output, which statement is correct?

Question 20mediummultiple choice
Study the full IPv6 explanation →
Interface GigabitEthernet0/1 is configured as shown:

interface GigabitEthernet0/1

ipv6 address 2001:db8:1::1/64 ipv6 nd raguard ipv6 nd prefix default no-autoconfig

What is the effect of this configuration?

Question 21mediummultiple choice
Read the full DHCP explanation →

Examine the following partial IPv6 DHCP guard configuration:

ipv6 dhcp guard policy DHCP_GUARD device-role server match server access-list SERVER_ACL

interface GigabitEthernet0/2

ipv6 dhcp guard policy DHCP_GUARD

Which statement is true about this configuration?

Question 22mediummultiple choice
Study the full IPv6 explanation →

A network engineer configures IPv6 Source Guard on an interface:

interface GigabitEthernet0/3

ipv6 verify source

What is the immediate effect of this command?

Question 23mediummultiple choice
Study the full IPv6 explanation →

Consider the following partial configuration:

ipv6 nd inspection policy ND_INSPECT device-role host trusted-port

interface GigabitEthernet0/4

ipv6 nd inspection policy ND_INSPECT

What is the effect of the 'trusted-port' command in this policy?

Question 24mediummultiple choice
Read the full DHCP explanation →

An engineer applies the following configuration to an interface:

interface GigabitEthernet0/5

ipv6 dhcp guard attach-policy DHCP_GUARD ipv6 snooping database file nvram:ipv6-snoop.db

Which statement is true?

Question 25mediummultiple choice
Study the full IPv6 explanation →

Which configuration is missing to properly implement IPv6 First Hop Security on an access switch port that should only allow traffic from a single host with a static IPv6 address 2001:db8:1::10?

Question 26easymultiple choice
Study the full IPv6 explanation →

What is the default role of an interface in IPv6 Neighbor Discovery Inspection when no policy is explicitly applied?

Question 27mediummultiple choice
Read the full DHCP explanation →

In IPv6 First Hop Security, what is the purpose of the 'device-role' command in a DHCP guard policy?

Question 28easymultiple choice
Study the full IPv6 explanation →

Which RFC defines the IPv6 Neighbor Discovery Protocol that is the basis for many First Hop Security features?

Question 29mediummulti select
Read the full DHCP explanation →

Which TWO commands can be used to verify the operation of IPv6 First Hop Security features such as RA Guard and DHCPv6 Guard on a Cisco IOS-XE switch? (Choose TWO.)

Question 30mediummulti select
Study the full IPv6 explanation →

Which TWO statements about IPv6 Neighbor Discovery (ND) Inspection are true? (Choose TWO.)

Question 31hardmulti select
Study the full IPv6 explanation →

Which TWO configuration steps are required to enable IPv6 RA Guard on a Cisco switch interface? (Choose TWO.)

More IPv6 First Hop Security questions available in the full practice test.

Continue Practising →
←

Previous objective

Control Plane Policing (CoPP)

Next objective

Infrastructure Services

→

All 300-410 Objectives

  • 100.Layer 3 Technologies35%
  • 101.EIGRP Troubleshooting
  • 102.OSPF Troubleshooting (v2/v3)
  • 103.BGP Troubleshooting
  • 104.Route Redistribution
  • 105.Policy-Based Routing (PBR)
  • 106.VRF-Lite
  • 107.Route Maps and Route Filtering
  • 108.Administrative Distance
  • 109.Route Summarization
  • 110.Bidirectional Forwarding Detection (BFD)
  • 200.VPN Technologies20%
  • 201.MPLS Operations
  • 202.MPLS L3VPN
  • 203.DMVPN
  • 204.IPsec Site-to-Site VPN
  • 205.IPv6 Tunneling Techniques
  • 300.Infrastructure Security20%
  • 301.Device Access Control
  • 302.IPv4 Access Control Lists
  • 303.IPv6 Traffic Filtering and uRPF
  • 304.Control Plane Policing (CoPP)
  • 305.IPv6 First Hop Security
  • 400.Infrastructure Services25%
  • 401.Device Management
  • 402.SNMP Troubleshooting
  • 403.Network Logging and Syslog
  • 404.Embedded Event Manager (EEM)
  • 405.IP SLA
  • 406.NetFlow and Flexible NetFlow
  • 407.SPAN, RSPAN, and ERSPAN
  • 408.DHCP (IPv4 and IPv6)
  • 409.NAT and PAT