Courseiva
hardMultiple SelectObjective-mapped

300-410 Practice Question: Which THREE statements about IPv6 Source Guard…

Which THREE statements about IPv6 Source Guard are true? (Choose THREE.)

⚠ Common exam trap

Cisco often tests the misconception that IPv6 Source Guard filters both inbound and outbound traffic, when in fact it only filters inbound traffic, and the trap here is assuming DHCPv6 snooping is mandatory when ND Inspection can also supply the binding table.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

It filters IPv6 traffic based on the source IPv6 address of incoming packets.

IPv6 Source Guard filters incoming IPv6 traffic on a per-port basis by examining the source IPv6 address of packets and comparing it against the IPv6 snooping binding table. If the source address does not match a valid binding, the packet is dropped, preventing spoofing attacks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • It filters IPv6 traffic based on the source IPv6 address of incoming packets.

    Why this is correct

    IPv6 Source Guard checks the source address against the binding table and drops packets with invalid source addresses.

  • It relies on the IPv6 snooping binding table, which is populated by DHCPv6 snooping or ND Inspection.

    Why this is correct

    The binding table is built from DHCPv6 snooping entries or ND Inspection, and Source Guard uses this table to validate traffic.

  • It can be configured to allow traffic from specific prefixes using a static prefix list.

    Why this is correct

    A static prefix list can be applied to permit traffic from certain prefixes, overriding dynamic entries.

  • It filters both incoming and outgoing IPv6 traffic on a port.

    Why it's wrong here

    IPv6 Source Guard filters only incoming traffic (ingress) to prevent spoofing; it does not filter outgoing traffic.

  • It requires DHCPv6 snooping to be enabled on the VLAN to function.

    Why it's wrong here

    While DHCPv6 snooping can populate the binding table, ND Inspection can also be used; DHCPv6 snooping is not strictly required.

About these practice questions

One of 1,966 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.