300-410 Infrastructure Services Practice Question
A network administrator is deploying IPv6 First Hop Security (FHS) on a Cisco Catalyst switch to mitigate rogue Router Advertisement (RA) attacks. The switch is running Cisco IOS Software and is configured with the command ipv6 nd raguard policy POLICY1. Which additional step is required to activate RA guard on an interface?
⚠ Common exam trap
The trap here is assuming that creating the policy is sufficient, or confusing the trust command with the attach-policy command.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Apply the policy to the interface using ipv6 nd raguard attach-policy POLICY1.
RA guard requires two steps: creating a policy that defines the filtering rules, and attaching that policy to an interface. The attach-policy command activates the policy on the specified interface. Other options are either unrelated features or modify trust settings, but they do not activate the policy on an interface.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure the interface as trusted using ipv6 nd raguard trust.
Why it's wrong here
The ipv6 nd raguard trust command is used to mark an interface as trusted, meaning RA messages received on it are not blocked. This is typically used on uplinks toward legitimate routers. However, it does not activate the policy on an interface; it modifies the behavior for trusted ports. Therefore, it is not the required step to activate RA guard.
- ✓
Apply the policy to the interface using ipv6 nd raguard attach-policy POLICY1.
Why this is correct
After creating an RA guard policy, you must attach it to the desired interface with the ipv6 nd raguard attach-policy command. This activates the policy on that interface, allowing it to filter rogue RAs. Without attaching the policy, the configuration exists but is not enforced on any port, leaving the network vulnerable.
- ✗
Enable IPv6 unicast routing globally with ipv6 unicast-routing.
Why it's wrong here
Enabling IPv6 unicast routing globally is not required for RA guard to function. RA guard operates at Layer 2 and inspects ICMPv6 RA messages regardless of whether the switch is routing IPv6. While IPv6 must be enabled on the switch, global routing is not a prerequisite for the RA guard feature.
- ✗
Enable DHCPv6 snooping globally with ipv6 dhcp snooping.
Why it's wrong here
DHCPv6 snooping is a separate First Hop Security feature that filters DHCPv6 messages. It does not activate RA guard. While both can be part of an IPv6 FHS deployment, enabling DHCPv6 snooping has no effect on RA guard policy enforcement. Thus, it is not the correct step to activate RA guard.
Go deeper
Related to this question
About these practice questions
This 300-410 question is part of Courseiva's 1,401-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.