hardMultiple SelectObjective-mapped
300-410 Practice Question: Which THREE statements about IPv6 Source Guard…
Which THREE statements about IPv6 Source Guard are true? (Choose THREE.)
⚠ Common exam trap
Cisco often tests the misconception that IPv6 Source Guard filters both inbound and outbound traffic, when in fact it only filters inbound traffic, and the trap here is assuming DHCPv6 snooping is mandatory when ND Inspection can also supply the binding table.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It filters IPv6 traffic based on the source IPv6 address of incoming packets.
IPv6 Source Guard filters incoming IPv6 traffic on a per-port basis by examining the source IPv6 address of packets and comparing it against the IPv6 snooping binding table. If the source address does not match a valid binding, the packet is dropped, preventing spoofing attacks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
It filters IPv6 traffic based on the source IPv6 address of incoming packets.
Why this is correct
IPv6 Source Guard checks the source address against the binding table and drops packets with invalid source addresses.
- ✓
It relies on the IPv6 snooping binding table, which is populated by DHCPv6 snooping or ND Inspection.
Why this is correct
The binding table is built from DHCPv6 snooping entries or ND Inspection, and Source Guard uses this table to validate traffic.
- ✓
It can be configured to allow traffic from specific prefixes using a static prefix list.
Why this is correct
A static prefix list can be applied to permit traffic from certain prefixes, overriding dynamic entries.
- ✗
It filters both incoming and outgoing IPv6 traffic on a port.
Why it's wrong here
IPv6 Source Guard filters only incoming traffic (ingress) to prevent spoofing; it does not filter outgoing traffic.
- ✗
It requires DHCPv6 snooping to be enabled on the VLAN to function.
Why it's wrong here
While DHCPv6 snooping can populate the binding table, ND Inspection can also be used; DHCPv6 snooping is not strictly required.
Go deeper
Related to this question
About these practice questions
One of 1,966 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.