Courseiva
hardMultiple SelectObjective-mapped

300-410 Practice Question: Which TWO statements about IPv6 First Hop…

Which TWO statements about IPv6 First Hop Security (FHS) Source Guard are true? (Choose TWO.)

⚠ Common exam trap

Cisco often tests the misconception that IPv6 Source Guard creates its own bindings or only works with DHCPv6, when in fact it relies on the binding table built by ND snooping and DHCPv6 snooping, and it filters based on source address, not destination.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

IPv6 Source Guard uses the IPv6 binding table to permit or deny traffic based on source address.

IPv6 Source Guard uses the IPv6 binding table (populated by ND snooping and/or DHCPv6 snooping) to permit or deny traffic based on the source IPv6 address in the packet. This prevents spoofing attacks by ensuring that only traffic from legitimate, learned source addresses is forwarded, similar to IPv4 Source Guard.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • IPv6 Source Guard dynamically creates binding entries for all IPv6 addresses learned via ND.

    Why it's wrong here

    Incorrect. Source Guard does not create bindings; it relies on DHCPv6 snooping or ND snooping to populate the binding table.

  • IPv6 Source Guard uses the IPv6 binding table to permit or deny traffic based on source address.

    Why this is correct

    Correct. Source Guard checks the source IPv6 address and MAC against the binding table and drops unauthorized traffic.

  • IPv6 Source Guard filters traffic based on the destination IPv6 address in the packet.

    Why it's wrong here

    Incorrect. Source Guard filters based on source address, not destination.

  • IPv6 Source Guard can be enabled on a per-interface or per-VLAN basis.

    Why this is correct

    Correct. The 'ipv6 source-guard' command can be applied to an interface or a VLAN.

  • IPv6 Source Guard only works with addresses learned via DHCPv6.

    Why it's wrong here

    Incorrect. It can also work with addresses learned via ND snooping, not just DHCPv6.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every 300-410 question from scratch — 1,966 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.