Courseiva
Infrastructure Services →hardMultiple Choice

300-410 Infrastructure Services Practice Question

A network administrator is deploying IPv6 First Hop Security features on a Cisco Catalyst switch. The goal is to prevent rogue DHCPv6 servers from assigning addresses to clients. The administrator configures DHCPv6 Guard on the switch. Which additional configuration is necessary to ensure that DHCPv6 Guard operates correctly?

⚠ Common exam trap

The trap here is assuming that DHCPv6 Guard can operate independently, when it actually depends on IPv6 snooping.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable IPv6 snooping globally.

DHCPv6 Guard requires IPv6 snooping to be enabled because it uses the snooping binding table to validate DHCPv6 server messages. Without IPv6 snooping, DHCPv6 Guard cannot inspect or filter DHCPv6 packets. The other options either do not address the requirement or are unrelated features. Thus, enabling IPv6 snooping globally is the necessary additional configuration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Apply an IPv6 access list to block DHCPv6 server traffic.

    Why it's wrong here

    An IPv6 access list can block DHCPv6 traffic, but it is a blunt instrument and does not provide the granular control of DHCPv6 Guard. DHCPv6 Guard can distinguish between trusted and untrusted ports and allow legitimate servers. An ACL would block all DHCPv6 server messages, including from legitimate servers, causing clients to fail to obtain addresses. Thus, an ACL is not the correct solution.

  • ✗

    Enable RA Guard on all switch ports.

    Why it's wrong here

    RA Guard prevents rogue IPv6 routers from sending Router Advertisement messages. It does not affect DHCPv6 servers. While both are IPv6 First Hop Security features, they address different threats. Enabling RA Guard would not help with DHCPv6 Guard; it is a separate feature. Therefore, this configuration is irrelevant to the scenario.

  • ✓

    Enable IPv6 snooping globally.

    Why this is correct

    DHCPv6 Guard relies on IPv6 snooping to function. IPv6 snooping builds a binding table that tracks legitimate DHCPv6 servers and clients. Without IPv6 snooping enabled, DHCPv6 Guard cannot inspect DHCPv6 messages or enforce policies. Therefore, enabling IPv6 snooping globally is a prerequisite for DHCPv6 Guard to operate correctly and block rogue servers.

  • ✗

    Configure a DHCPv6 relay agent on the switch.

    Why it's wrong here

    A DHCPv6 relay agent is used to forward DHCPv6 messages between clients and servers on different subnets. It is not required for DHCPv6 Guard, which is a security feature that filters DHCPv6 server messages on the local link. In fact, enabling a relay agent would not help prevent rogue servers; it would simply forward messages, potentially including those from rogue servers.

About these practice questions

This 300-410 question is part of Courseiva's 1,401-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.