mediumMultiple Select
300-410 Practice Question: Which TWO statements about IPv6 Neighbor…
Which TWO statements about IPv6 Neighbor Discovery (ND) Inspection are true? (Choose TWO.)
⚠ Common exam trap
Cisco often tests the distinction between IPv6 First Hop Security features, and the trap here is confusing ND Inspection (which validates ND messages) with DHCPv6 Guard (which blocks rogue DHCPv6 servers) or RA Guard (which uses prefix lists).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It validates Neighbor Solicitation and Neighbor Advertisement messages against the IPv6 snooping binding table.
Option A is correct because IPv6 ND Inspection builds a binding table (IPv6 address to MAC address mappings learned from DHCPv6 snooping or ND messages) and validates Neighbor Solicitation and Neighbor Advertisement messages against that table, dropping messages whose source link-layer address does not match the binding. Option B is correct because ND Inspection supports per-interface configuration, including the ability to rate-limit ND packets (using the ipv6 nd inspection limit rate command) to mitigate ND flooding and DoS attacks. Option C is not correct because blocking rogue DHCPv6 servers is the function of DHCPv6 Guard, not ND Inspection. Option D is not correct because ND Inspection relies on the IPv6 snooping binding table rather than a prefix list to validate addresses. Option E is not correct because ND Inspection is configured on a per-interface basis (with a global policy applied to interfaces), not globally only.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
It validates Neighbor Solicitation and Neighbor Advertisement messages against the IPv6 snooping binding table.
Why this is correct
Neighbor Discovery Inspection builds a snooping binding table from DHCPv6 or static entries, then filters Neighbor Solicitation and Neighbor Advertisement messages whose source addresses lack a matching binding, blocking spoofed link-layer address claims. This satisfies the stem's requirement for statements accurately describing ND Inspection behaviour on Cisco switches.
- ✓
It can be configured to rate-limit ND packets on a per-interface basis.
Why this is correct
Rate-limiting ND packets per interface is a genuine ND Inspection capability, letting you cap Neighbor Solicitation and Advertisement traffic to blunt ND exhaustion and spoofing floods. This satisfies the stem's requirement for a true statement, since the feature applies policing at the interface level rather than only validating bindings.
- ✗
It prevents rogue DHCPv6 servers from assigning malicious addresses.
Why it's wrong here
ND Inspection validates ICMPv6 Neighbor Solicitation and Advertisement messages against the binding table; it does not police DHCPv6 server traffic. It is tempting because rogue DHCPv6 servers are a real threat, but that is handled by DHCPv6 Guard, which filters server advertisements on untrusted ports.
- ✗
It uses a prefix list to determine which source addresses are allowed.
Why it's wrong here
ND Inspection builds its binding table from snooped Neighbor Discovery messages and uses a policy (trusted/untrusted) plus optional static bindings, not a prefix list of permitted source addresses. A prefix list is tempting because IPv6 access lists and RA Guard policies do filter by prefix, but that is a different feature.
- ✗
It is enabled globally and cannot be applied on a per-interface basis.
Why it's wrong here
ND Inspection is configured per interface (or per VLAN) with ipv6 nd inspection, marking ports trusted or untrusted, so it is not a global-only feature. It is tempting because some IPv6 first-hop security features are enabled globally, but interface-level policy is precisely how ND Inspection scopes its enforcement.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
This 300-410 question is part of Courseiva's 1,401-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.