Courseiva
mediumMultiple SelectObjective-mapped

300-410 Practice Question: Which TWO commands can be used to verify the…

Which TWO commands can be used to verify the operation of IPv6 First Hop Security features such as RA Guard and DHCPv6 Guard on a Cisco IOS-XE switch? (Choose TWO.)

⚠ Common exam trap

Cisco often tests the distinction between the generic 'show ipv6 snooping' command and the specific but non-existent 'show ipv6 nd raguard' command, leading candidates to incorrectly assume each FHS feature has its own dedicated show command.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

show ipv6 snooping

The 'show ipv6 snooping' command is the primary verification tool for IPv6 First Hop Security (FHS) features, including RA Guard and DHCPv6 Guard. It displays the IPv6 snooping policy database, which tracks all discovered IPv6 neighbors and their binding states, directly reflecting the operational status of RA Guard and DHCPv6 Guard enforcement on the switch.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • show ipv6 snooping

    Why this is correct

    This command displays the operational status of IPv6 snooping features, including RA Guard and DHCPv6 Guard, and is a primary verification tool.

  • show ipv6 dhcp guard

    Why this is correct

    This command shows the DHCPv6 Guard configuration and statistics, confirming whether the feature is active and blocking unauthorized DHCP servers.

  • show ipv6 nd raguard

    Why it's wrong here

    This is not a valid Cisco IOS command; the correct command to verify RA Guard is 'show ipv6 snooping' or 'show ipv6 nd raguard policy' (with policy name), but not standalone.

  • show ipv6 dhcp binding

    Why it's wrong here

    This command shows DHCPv6 client bindings, not the guard feature itself; it is used for DHCPv6 server verification, not FHS.

  • show ipv6 source guard

    Why it's wrong here

    This command is used for IPv6 Source Guard, which is a separate FHS feature; it does not verify RA Guard or DHCPv6 Guard.

About these practice questions

Courseiva writes every 300-410 question from scratch — 1,966 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.