Courseiva
mediumMultiple SelectObjective-mapped

300-410 Practice Question: Which THREE symptoms indicate that IPv6 First Hop…

Which THREE symptoms indicate that IPv6 First Hop Security features are misconfigured or not functioning correctly? (Choose THREE.)

⚠ Common exam trap

Cisco often tests the distinction between First Hop Security failures (which block control-plane messages like RAs and DHCPv6) and other IPv6 issues like routing problems or DAD collisions, so candidates must recognize that symptoms like inter-host ping success but router ping failure point to routing, not First Hop Security.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

IPv6 hosts on a segment are unable to obtain a global unicast address via SLAAC, even though a legitimate router is present.

SLAAC relies on Router Advertisements (RAs) to provide the prefix and other configuration information. If IPv6 First Hop Security features such as RA Guard or RA snooping are misconfigured, they may block or drop legitimate RAs, preventing hosts from generating a global unicast address via SLAAC even though a valid router is present.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • IPv6 hosts on a segment are unable to obtain a global unicast address via SLAAC, even though a legitimate router is present.

    Why this is correct

    This could be due to RA Guard blocking the router's Router Advertisements, preventing SLAAC.

  • A newly connected switch causes existing hosts to lose IPv6 connectivity to the default gateway.

    Why this is correct

    This may indicate ND Inspection or IPv6 Source Guard dropping valid ND packets from the new switch, or a binding table issue.

  • Hosts on a VLAN receive Router Advertisements but do not update their default gateway.

    Why this is correct

    RA Guard can be configured to drop RAs from unauthorized sources, or the policy may incorrectly mark the legitimate router as a host, causing hosts to ignore the RAs.

  • IPv6 pings between two hosts on the same VLAN succeed, but pings to the router fail.

    Why it's wrong here

    This could be a routing or gateway issue, but not necessarily an FHS problem; FHS typically blocks at Layer 2, not Layer 3 forwarding.

  • The switch logs show frequent 'IPv6 address collision' messages.

    Why it's wrong here

    Address collisions are typically detected by DAD (Duplicate Address Detection) and are not directly caused by FHS misconfiguration; they indicate a different issue.

About these practice questions

One of 1,966 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.