300-410 Infrastructure Security Practice Question
A network engineer is configuring an IPv6 First Hop Security feature on a Cisco Catalyst switch to prevent rogue devices from sending Router Advertisement messages with a prefix that conflicts with the legitimate prefix. The engineer wants to ensure that only authorized routers can advertise prefixes, while still allowing hosts to perform SLAAC. Which feature should be implemented?
⚠ Common exam trap
Watch out — candidates often confuse RA Guard with other IPv6 First Hop Security features like DHCP Guard or Source Guard, which protect against different rogue device behaviors.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
IPv6 RA Guard
The requirement is to prevent rogue devices from sending Router Advertisement messages with conflicting prefixes while allowing legitimate routers and SLAAC. IPv6 RA Guard is designed specifically to filter RA and Redirect messages on untrusted ports, ensuring only authorized routers can advertise. The other features address different threats such as source spoofing, rogue DHCPv6 servers, or ND cache exhaustion.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
IPv6 Source Guard
Why it's wrong here
IPv6 Source Guard validates the source address of IPv6 traffic against the DHCPv6 snooping or Neighbor Discovery snooping binding table. It does not inspect Router Advertisement messages or enforce prefix ownership. In this scenario, the goal is to prevent rogue RA messages, which is not addressed by Source Guard. Therefore, it fails to meet the requirement.
- ✗
IPv6 DHCP Guard
Why it's wrong here
IPv6 DHCP Guard blocks DHCPv6 server messages from unauthorized ports to prevent rogue DHCPv6 servers. It does not inspect Router Advertisements or enforce prefix ownership. Since the threat is rogue RAs, DHCP Guard is not applicable. Thus, it does not satisfy the requirement to control RA messages.
- ✗
IPv6 Destination Guard
Why it's wrong here
IPv6 Destination Guard enforces address resolution by dropping traffic to destinations not in the binding table, mitigating ND cache exhaustion attacks. It does not filter Router Advertisements or validate prefix advertisements. Therefore, it is not the correct feature to prevent rogue RA messages in this scenario.
- ✓
IPv6 RA Guard
Why this is correct
IPv6 RA Guard filters Router Advertisement and Redirect messages on ports where they are not expected. It can be configured to block RAs from unauthorized devices while allowing legitimate routers. This directly prevents rogue devices from advertising conflicting prefixes and is the correct solution for the stated requirement.
Go deeper
Related to this question
About these practice questions
One of 1,401 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.