Courseiva
mediumMultiple Select

300-410 Practice Question: Which TWO statements about IPv6 Neighbor…

Which TWO statements about IPv6 Neighbor Discovery (ND) Inspection are true? (Choose TWO.)

⚠ Common exam trap

Cisco often tests the distinction between IPv6 First Hop Security features, and the trap here is confusing ND Inspection (which validates ND messages) with DHCPv6 Guard (which blocks rogue DHCPv6 servers) or RA Guard (which uses prefix lists).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It validates Neighbor Solicitation and Neighbor Advertisement messages against the IPv6 snooping binding table.

Option A is correct because IPv6 ND Inspection builds a binding table (IPv6 address to MAC address mappings learned from DHCPv6 snooping or ND messages) and validates Neighbor Solicitation and Neighbor Advertisement messages against that table, dropping messages whose source link-layer address does not match the binding. Option B is correct because ND Inspection supports per-interface configuration, including the ability to rate-limit ND packets (using the ipv6 nd inspection limit rate command) to mitigate ND flooding and DoS attacks. Option C is not correct because blocking rogue DHCPv6 servers is the function of DHCPv6 Guard, not ND Inspection. Option D is not correct because ND Inspection relies on the IPv6 snooping binding table rather than a prefix list to validate addresses. Option E is not correct because ND Inspection is configured on a per-interface basis (with a global policy applied to interfaces), not globally only.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    It validates Neighbor Solicitation and Neighbor Advertisement messages against the IPv6 snooping binding table.

    Why this is correct

    Neighbor Discovery Inspection builds a snooping binding table from DHCPv6 or static entries, then filters Neighbor Solicitation and Neighbor Advertisement messages whose source addresses lack a matching binding, blocking spoofed link-layer address claims. This satisfies the stem's requirement for statements accurately describing ND Inspection behaviour on Cisco switches.

  • ✓

    It can be configured to rate-limit ND packets on a per-interface basis.

    Why this is correct

    Rate-limiting ND packets per interface is a genuine ND Inspection capability, letting you cap Neighbor Solicitation and Advertisement traffic to blunt ND exhaustion and spoofing floods. This satisfies the stem's requirement for a true statement, since the feature applies policing at the interface level rather than only validating bindings.

  • ✗

    It prevents rogue DHCPv6 servers from assigning malicious addresses.

    Why it's wrong here

    ND Inspection validates ICMPv6 Neighbor Solicitation and Advertisement messages against the binding table; it does not police DHCPv6 server traffic. It is tempting because rogue DHCPv6 servers are a real threat, but that is handled by DHCPv6 Guard, which filters server advertisements on untrusted ports.

  • ✗

    It uses a prefix list to determine which source addresses are allowed.

    Why it's wrong here

    ND Inspection builds its binding table from snooped Neighbor Discovery messages and uses a policy (trusted/untrusted) plus optional static bindings, not a prefix list of permitted source addresses. A prefix list is tempting because IPv6 access lists and RA Guard policies do filter by prefix, but that is a different feature.

  • ✗

    It is enabled globally and cannot be applied on a per-interface basis.

    Why it's wrong here

    ND Inspection is configured per interface (or per VLAN) with ipv6 nd inspection, marking ports trusted or untrusted, so it is not a global-only feature. It is tempting because some IPv6 first-hop security features are enabled globally, but interface-level policy is precisely how ND Inspection scopes its enforcement.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

This 300-410 question is part of Courseiva's 1,401-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.