mediumMultiple SelectObjective-mapped
300-410 Practice Question: Which TWO commands can be used to verify the…
Which TWO commands can be used to verify the operation of IPv6 First Hop Security features such as RA Guard and DHCPv6 Guard on a Cisco IOS-XE switch? (Choose TWO.)
⚠ Common exam trap
Cisco often tests the distinction between the generic 'show ipv6 snooping' command and the specific but non-existent 'show ipv6 nd raguard' command, leading candidates to incorrectly assume each FHS feature has its own dedicated show command.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
show ipv6 snooping
The 'show ipv6 snooping' command is the primary verification tool for IPv6 First Hop Security (FHS) features, including RA Guard and DHCPv6 Guard. It displays the IPv6 snooping policy database, which tracks all discovered IPv6 neighbors and their binding states, directly reflecting the operational status of RA Guard and DHCPv6 Guard enforcement on the switch.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
show ipv6 snooping
Why this is correct
This command displays the operational status of IPv6 snooping features, including RA Guard and DHCPv6 Guard, and is a primary verification tool.
- ✓
show ipv6 dhcp guard
Why this is correct
This command shows the DHCPv6 Guard configuration and statistics, confirming whether the feature is active and blocking unauthorized DHCP servers.
- ✗
show ipv6 nd raguard
Why it's wrong here
This is not a valid Cisco IOS command; the correct command to verify RA Guard is 'show ipv6 snooping' or 'show ipv6 nd raguard policy' (with policy name), but not standalone.
- ✗
show ipv6 dhcp binding
Why it's wrong here
This command shows DHCPv6 client bindings, not the guard feature itself; it is used for DHCPv6 server verification, not FHS.
- ✗
show ipv6 source guard
Why it's wrong here
This command is used for IPv6 Source Guard, which is a separate FHS feature; it does not verify RA Guard or DHCPv6 Guard.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 300-410 question from scratch — 1,966 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.