IPv6 questions test address types (global unicast, link-local, multicast, anycast), address assignment (SLAAC, DHCPv6, EUI-64), OSPFv3, and dual-stack. The CCNA often presents an IPv6 address and asks you to identify the prefix, type, or calculate the EUI-64 interface ID.
Start Scenario PracticeA network engineer runs the following command to verify IPv6 traffic filtering with logging: R1# show logging | include FILTER *Mar 1 00:04:56.789: %IPV6_ACL-6-ACCESSLOGDP: list FILTER denied tcp 2001:DB8:2::1(12345) -> 2001:DB8:3::1(80), 1 packet What does this output indicate?
Explanation: The log message shows an IPv6 ACL (named FILTER) logging a denied TCP packet from source 2001:DB8:2::1 port 12345 to destination 2001:DB8:3::1 port 80. The keyword 'denied' in the log entry confirms the packet was blocked by the access list, making option A correct.
A network engineer runs the following command to troubleshoot DHCPv6 address assignment on router R1: R1# show ipv6 dhcp binding Output: Client: FE80::21A:2BFF:FE3C:4D01 DUID: 0003000121A2B3C4D5E6 Username: unassigned VRF: default IA NA: IA ID 0x00040001, T1 302400, T2 483840 Address: 2001:DB8:1::100 Preferred lifetime 604800, valid lifetime 2592000 Expires at Mar 01 2025 12:00 PM (2592000 seconds) IA PD: IA ID 0x00040002, T1 302400, T2 483840 Prefix: 2001:DB8:1::/48 Preferred lifetime 604800, valid lifetime 2592000 Expires at Mar 01 2025 12:00 PM (2592000 seconds) What does this output indicate?
Explanation: The output shows both an IA_NA (Identity Association for Non-temporary Address) with an IPv6 address (2001:DB8:1::100) and an IA_PD (Identity Association for Prefix Delegation) with a prefix (2001:DB8:1::/48). This confirms that the DHCPv6 server has assigned both a global unicast address and a delegated prefix to the client, making option B correct.
A network engineer runs the following command to troubleshoot DHCPv6 relay on router R1: R1# debug ipv6 dhcp relay Output: IPv6 DHCP relay: Received SOLICIT message from FE80::1 on GigabitEthernet0/0 IPv6 DHCP relay: Forwarding SOLICIT to server 2001:DB8:2::1 via GigabitEthernet0/1 IPv6 DHCP relay: Received ADVERTISE message from server 2001:DB8:2::1 via GigabitEthernet0/1 IPv6 DHCP relay: Forwarding ADVERTISE to client FE80::1 via GigabitEthernet0/0 IPv6 DHCP relay: Received REQUEST message from FE80::1 on GigabitEthernet0/0 IPv6 DHCP relay: Forwarding REQUEST to server 2001:DB8:2::1 via GigabitEthernet0/1 IPv6 DHCP relay: Received REPLY message from server 2001:DB8:2::1 via GigabitEthernet0/1 IPv6 DHCP relay: Forwarding REPLY to client FE80::1 via GigabitEthernet0/0 What does this output indicate?
Explanation: The debug output shows a complete DHCPv6 four-message exchange (SOLICIT-ADVERTISE-REQUEST-REPLY) being relayed between the client (FE80::1) and the server (2001:DB8:2::1). Each message is received on one interface and forwarded out the other, confirming the relay agent is functioning correctly. Therefore, option B is correct.
An engineer applies the following configuration to an interface: interface GigabitEthernet0/5 ipv6 dhcp guard attach-policy DHCP_GUARD ipv6 snooping database file nvram:ipv6-snoop.db Which statement is true?
Explanation: The 'ipv6 dhcp guard attach-policy DHCP_GUARD' command applies the DHCP Guard policy to the interface, and the 'ipv6 snooping database file nvram:ipv6-snoop.db' command configures the snooping database to be stored in NVRAM. These two commands operate independently; the DHCP Guard policy is enforced immediately upon attachment, regardless of the database's presence or population state.
In IPv6 First Hop Security, what is the purpose of the 'device-role' command in a DHCP guard policy?
Explanation: The 'device-role' command in a DHCP guard policy specifies the role of the interface as either a DHCP server, client, or relay. This allows the switch to filter DHCP messages based on the expected role, blocking unauthorized DHCP server messages on interfaces that should only have clients or relays. It is a key component of IPv6 First Hop Security to prevent rogue DHCPv6 servers.
+10 more scenario questions available
Practice all IPv6 Configuration ScenariosIPv6 questions test address types (global unicast, link-local, multicast, anycast), address assignment (SLAAC, DHCPv6, EUI-64), OSPFv3, and dual-stack. The CCNA often presents an IPv6 address and asks you to identify the prefix, type, or calculate the EUI-64 interface ID. These appear throughout the 300-410 and require you to apply your knowledge, not just recall facts.
Cisco doesn't publish an exact breakdown, but scenario-based questions (especially exhibit and command-output formats) make up a significant portion of the 300-410. Practicing each scenario type ensures you're ready for any format.
Yes. Courseiva provides free 300-410 scenario practice across all official exam domains. The platform includes scenario-based questions, command-output interpretation, topic-based practice, mock exams, and readiness tracking — no account required.
Launch a full IPv6 Configuration Scenarios session with instant scoring and detailed explanations.
Start Scenario Practice →