hardMultiple ChoiceObjective-mapped
300-410 Practice Question: Runs the following command to troubleshoot IPv6…
A network engineer runs the following command to troubleshoot IPv6 ND inspection:
R1# debug ipv6 nd inspection *Mar 1 00:02:34.567: IPv6-ND-Inspection: R1, Fa0/0, NS from fe80::1 to ff02::1, target 2001:db8::1, options: SLLA 0011.2233.4455 *Mar 1 00:02:34.567: IPv6-ND-Inspection: R1, Fa0/0, NS from fe80::1 to ff02::1, target 2001:db8::1, SLLA 0011.2233.4455 is allowed by policy INSPECT *Mar 1 00:02:35.890: IPv6-ND-Inspection: R1, Fa0/0, NA from fe80::2 to fe80::1, target 2001:db8::2, options: TLLA 00aa.bbcc.ddee *Mar 1 00:02:35.890: IPv6-ND-Inspection: R1, Fa0/0, NA from fe80::2 to fe80::1, target 2001:db8::2, TLLA 00aa.bbcc.ddee is blocked by policy INSPECT
What does this output indicate?
⚠ Common exam trap
Cisco often tests the distinction between NS and NA handling in ND inspection, where candidates may assume both messages are treated identically, but the policy can allow one and block the other based on binding table validation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ND inspection is allowing NS messages but blocking NA messages from fe80::2, likely due to a MAC address mismatch or policy violation.
The debug output shows that the Neighbor Solicitation (NS) from fe80::1 is allowed by policy INSPECT, while the Neighbor Advertisement (NA) from fe80::2 is blocked by the same policy. This indicates that IPv6 ND inspection is selectively permitting NS messages but denying NA messages from fe80::2, likely due to a MAC address mismatch (the TLLA in the NA does not match the expected binding) or a policy violation, making option A correct.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
ND inspection is allowing NS messages but blocking NA messages from fe80::2, likely due to a MAC address mismatch or policy violation.
Why this is correct
The NA is blocked, which could be due to the source MAC not matching the TLLA or policy rules.
- ✗
ND inspection is blocking all NS and NA messages, indicating a misconfiguration.
Why it's wrong here
The NS from fe80::1 is allowed, so not all messages are blocked.
- ✗
ND inspection is allowing all messages but logging them for analysis.
Why it's wrong here
The NA is explicitly blocked, so not all are allowed.
- ✗
ND inspection is not configured; the debug output is from default ND behavior.
Why it's wrong here
The debug references policy INSPECT, indicating ND inspection is configured.
Visual reference
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
This 300-410 question is part of Courseiva's 1,966-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.