hardMultiple Select
300-410 Practice Question: Which THREE statements about IPv6 Source Guard…
Which THREE statements about IPv6 Source Guard are true? (Choose THREE.)
⚠ Common exam trap
Cisco often tests the misconception that IPv6 Source Guard filters both inbound and outbound traffic, when in fact it only filters inbound traffic, and the trap here is assuming DHCPv6 snooping is mandatory when ND Inspection can also supply the binding table.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It filters IPv6 traffic based on the source IPv6 address of incoming packets.
Option A is correct because IPv6 Source Guard is a Layer 2 security feature that inspects incoming frames and drops those whose source IPv6 address does not match an entry in the IPv6 snooping binding table. Option B is correct because that binding table is the foundation of the feature, and it is populated dynamically by DHCPv6 snooping (for DHCPv6-assigned addresses) or by IPv6 ND Inspection (for statelessly autoconfigured or manually configured addresses). Option C is correct because IPv6 Source Guard supports a static prefix list, allowing an administrator to permit traffic from specific IPv6 prefixes in addition to the addresses learned in the binding table. Option D is not correct because IPv6 Source Guard operates only on ingress (incoming) traffic on a port, not on outgoing traffic. Option E is not correct because DHCPv6 snooping is not mandatory; the binding table can also be populated by ND Inspection, so the feature can function without DHCPv6 snooping being enabled on the VLAN.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
It filters IPv6 traffic based on the source IPv6 address of incoming packets.
Why this is correct
IPv6 Source Guard inspects incoming packets and drops those whose source IPv6 address is not present in the IPv6 snooping binding table, filtering strictly on the source address field rather than destination or traffic type.
- ✓
It relies on the IPv6 snooping binding table, which is populated by DHCPv6 snooping or ND Inspection.
Why this is correct
IPv6 Source Guard validates source addresses against the IPv6 snooping binding table, which is built dynamically by DHCPv6 snooping or ND Inspection; without these population mechanisms, the table stays empty and legitimate traffic is dropped.
- ✓
It can be configured to allow traffic from specific prefixes using a static prefix list.
Why this is correct
Static prefix lists let Source Guard permit known good prefixes without DHCP snooping bindings, satisfying the requirement to allow traffic from specific prefixes on trusted links where hosts use statically assigned or prefix-based addressing rather than snooped addresses.
- ✗
It filters both incoming and outgoing IPv6 traffic on a port.
Why it's wrong here
IPv6 Source Guard validates the source address of incoming IPv6 traffic against the snooping binding table; it does not inspect or filter outgoing traffic. It is tempting because guard features are often assumed bidirectional, but Source Guard operates solely on ingress. Egress filtering would require a separate ACL or destination guard construct.
- ✗
It requires DHCPv6 snooping to be enabled on the VLAN to function.
Why it's wrong here
IPv6 Source Guard can operate using the binding table populated by DHCPv6 snooping, but it also supports static binding entries and ND snooping, so DHCPv6 snooping is not mandatory. It is tempting because DHCPv6 snooping is the usual source of dynamic bindings, and in deployments relying solely on DHCPv6-assigned addresses it would be required.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 1,401 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.