hardMultiple Choice
300-410 Practice Question: Runs the following command to troubleshoot IPv6…
A network engineer runs the following command to troubleshoot IPv6 ND inspection:
R1# debug ipv6 nd inspection *Mar 1 00:02:34.567: IPv6-ND-Inspection: R1, Fa0/0, NS from fe80::1 to ff02::1, target 2001:db8::1, options: SLLA 0011.2233.4455 *Mar 1 00:02:34.567: IPv6-ND-Inspection: R1, Fa0/0, NS from fe80::1 to ff02::1, target 2001:db8::1, SLLA 0011.2233.4455 is allowed by policy INSPECT *Mar 1 00:02:35.890: IPv6-ND-Inspection: R1, Fa0/0, NA from fe80::2 to fe80::1, target 2001:db8::2, options: TLLA 00aa.bbcc.ddee *Mar 1 00:02:35.890: IPv6-ND-Inspection: R1, Fa0/0, NA from fe80::2 to fe80::1, target 2001:db8::2, TLLA 00aa.bbcc.ddee is blocked by policy INSPECT
What does this output indicate?
⚠ Common exam trap
Cisco often tests the distinction between NS and NA handling in ND inspection, where candidates may assume both messages are treated identically, but the policy can allow one and block the other based on binding table validation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ND inspection is allowing NS messages but blocking NA messages from fe80::2, likely due to a MAC address mismatch or policy violation.
The debug output shows that the Neighbor Solicitation (NS) from fe80::1 is allowed by policy INSPECT, while the Neighbor Advertisement (NA) from fe80::2 is blocked by the same policy. This indicates that IPv6 ND inspection is selectively permitting NS messages but denying NA messages from fe80::2, likely due to a MAC address mismatch (the TLLA in the NA does not match the expected binding) or a policy violation, making option A correct.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
ND inspection is allowing NS messages but blocking NA messages from fe80::2, likely due to a MAC address mismatch or policy violation.
Why this is correct
The debug shows the NS from fe80::1 permitted, while the NA from fe80::2 is blocked by policy INSPECT. ND inspection validates the source link-layer address against the binding table, so a mismatch between the advertised MAC and the recorded entry triggers the drop.
- ✗
ND inspection is blocking all NS and NA messages, indicating a misconfiguration.
Why it's wrong here
The debug shows the NS allowed and only the NA blocked by policy INSPECT, so inspection is selectively filtering, not blocking all NS and NA messages. It is tempting because a blocked NA suggests a policy problem, and would be correct if every NS and NA in the output carried a blocked result.
- ✗
ND inspection is allowing all messages but logging them for analysis.
Why it's wrong here
The output shows one NS allowed and one NA explicitly blocked by policy INSPECT, so inspection is enforcing policy rather than allowing everything. It is tempting because debug output is often used purely for logging, and would be correct if every message were permitted with logging only.
- ✗
ND inspection is not configured; the debug output is from default ND behavior.
Why it's wrong here
Messages are matched against a named policy INSPECT and one is blocked, which only occurs when ND inspection is configured and active. It is tempting because default ND behaviour generates similar NS and NA traffic, and would be correct if no policy decisions appeared in the debug output.
Visual reference
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
This 300-410 question is part of Courseiva's 1,401-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.