Courseiva
hardMultiple ChoiceObjective-mapped

300-410 Practice Question: Runs the following command to troubleshoot IPv6…

A network engineer runs the following command to troubleshoot IPv6 ND inspection:

R1# debug ipv6 nd inspection

*Mar  1 00:02:34.567: IPv6-ND-Inspection: R1, Fa0/0, NS from fe80::1 to ff02::1, target 2001:db8::1, options: SLLA 0011.2233.4455
*Mar  1 00:02:34.567: IPv6-ND-Inspection: R1, Fa0/0, NS from fe80::1 to ff02::1, target 2001:db8::1, SLLA 0011.2233.4455 is allowed by policy INSPECT
*Mar  1 00:02:35.890: IPv6-ND-Inspection: R1, Fa0/0, NA from fe80::2 to fe80::1, target 2001:db8::2, options: TLLA 00aa.bbcc.ddee
*Mar  1 00:02:35.890: IPv6-ND-Inspection: R1, Fa0/0, NA from fe80::2 to fe80::1, target 2001:db8::2, TLLA 00aa.bbcc.ddee is blocked by policy INSPECT

What does this output indicate?

⚠ Common exam trap

Cisco often tests the distinction between NS and NA handling in ND inspection, where candidates may assume both messages are treated identically, but the policy can allow one and block the other based on binding table validation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

ND inspection is allowing NS messages but blocking NA messages from fe80::2, likely due to a MAC address mismatch or policy violation.

The debug output shows that the Neighbor Solicitation (NS) from fe80::1 is allowed by policy INSPECT, while the Neighbor Advertisement (NA) from fe80::2 is blocked by the same policy. This indicates that IPv6 ND inspection is selectively permitting NS messages but denying NA messages from fe80::2, likely due to a MAC address mismatch (the TLLA in the NA does not match the expected binding) or a policy violation, making option A correct.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ND inspection is allowing NS messages but blocking NA messages from fe80::2, likely due to a MAC address mismatch or policy violation.

    Why this is correct

    The NA is blocked, which could be due to the source MAC not matching the TLLA or policy rules.

  • ND inspection is blocking all NS and NA messages, indicating a misconfiguration.

    Why it's wrong here

    The NS from fe80::1 is allowed, so not all messages are blocked.

  • ND inspection is allowing all messages but logging them for analysis.

    Why it's wrong here

    The NA is explicitly blocked, so not all are allowed.

  • ND inspection is not configured; the debug output is from default ND behavior.

    Why it's wrong here

    The debug references policy INSPECT, indicating ND inspection is configured.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

This 300-410 question is part of Courseiva's 1,966-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.