Courseiva
Infrastructure Security →mediumMultiple Choice

300-410 Infrastructure Security Practice Question

A network engineer is configuring an IPv6 First Hop Security feature on a Cisco Catalyst switch to prevent rogue devices from sending Router Advertisement messages with a prefix that conflicts with the legitimate prefix. The engineer wants to ensure that only authorized routers can advertise prefixes, while still allowing hosts to perform SLAAC. Which feature should be implemented?

⚠ Common exam trap

Watch out — candidates often confuse RA Guard with other IPv6 First Hop Security features like DHCP Guard or Source Guard, which protect against different rogue device behaviors.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

IPv6 RA Guard

The requirement is to prevent rogue devices from sending Router Advertisement messages with conflicting prefixes while allowing legitimate routers and SLAAC. IPv6 RA Guard is designed specifically to filter RA and Redirect messages on untrusted ports, ensuring only authorized routers can advertise. The other features address different threats such as source spoofing, rogue DHCPv6 servers, or ND cache exhaustion.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    IPv6 Source Guard

    Why it's wrong here

    IPv6 Source Guard validates the source address of IPv6 traffic against the DHCPv6 snooping or Neighbor Discovery snooping binding table. It does not inspect Router Advertisement messages or enforce prefix ownership. In this scenario, the goal is to prevent rogue RA messages, which is not addressed by Source Guard. Therefore, it fails to meet the requirement.

  • ✗

    IPv6 DHCP Guard

    Why it's wrong here

    IPv6 DHCP Guard blocks DHCPv6 server messages from unauthorized ports to prevent rogue DHCPv6 servers. It does not inspect Router Advertisements or enforce prefix ownership. Since the threat is rogue RAs, DHCP Guard is not applicable. Thus, it does not satisfy the requirement to control RA messages.

  • ✗

    IPv6 Destination Guard

    Why it's wrong here

    IPv6 Destination Guard enforces address resolution by dropping traffic to destinations not in the binding table, mitigating ND cache exhaustion attacks. It does not filter Router Advertisements or validate prefix advertisements. Therefore, it is not the correct feature to prevent rogue RA messages in this scenario.

  • ✓

    IPv6 RA Guard

    Why this is correct

    IPv6 RA Guard filters Router Advertisement and Redirect messages on ports where they are not expected. It can be configured to block RAs from unauthorized devices while allowing legitimate routers. This directly prevents rogue devices from advertising conflicting prefixes and is the correct solution for the stated requirement.

About these practice questions

One of 1,401 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.