Courseiva
mediumMultiple Choice

300-410 Practice Question: An engineer is troubleshooting a network where…

An engineer is troubleshooting a network where IPv6 hosts on VLAN 20 are unable to communicate with each other. The switch is configured with IPv6 First Hop Security features including Private VLAN (PVLAN) and IPv6 Source Guard. The hosts are in the same VLAN but cannot ping each other. What is the most likely cause?

⚠ Common exam trap

Cisco often tests the misconception that IPv6 Source Guard or RA Guard blocks all inter-host traffic, when in fact Private VLAN is the feature specifically designed to isolate hosts within the same VLAN at Layer 2.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The switch has Private VLAN configured on VLAN 20, and the hosts are on isolated ports, which prevents direct communication.

Private VLAN (PVLAN) on VLAN 20 isolates ports within the same VLAN, preventing direct communication between hosts on isolated ports. Even though the hosts share the same VLAN, PVLAN restricts traffic so that isolated ports can only communicate with a promiscuous port (e.g., a router uplink), not with each other. This directly explains why IPv6 hosts on VLAN 20 cannot ping each other.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The switch has Private VLAN configured on VLAN 20, and the hosts are on isolated ports, which prevents direct communication.

    Why this is correct

    Private VLAN isolated ports permit communication only with promiscuous ports, not with each other. Hosts on isolated ports within VLAN 20 therefore cannot exchange traffic despite sharing a subnet, which explains the failed pings; IPv6 Source Guard would instead filter spoofed source addresses.

  • ✗

    IPv6 Source Guard is blocking inter-host traffic because the hosts' bindings are not in the binding table.

    Why it's wrong here

    IPv6 Source Guard drops traffic whose source address lacks a binding-table entry, but it validates the source, not the destination, so it would not stop host-to-host pings between validly bound hosts. It is correct for preventing source-address spoofing, not for isolating hosts within a VLAN.

  • ✗

    RA Guard is blocking Neighbor Advertisements between hosts.

    Why it's wrong here

    RA Guard filters Router Advertisement and Redirect messages on access ports; Neighbor Advertisements between hosts are unaffected. It is the correct control for blocking rogue routers advertising on a VLAN, not for stopping Neighbor Discovery between hosts.

  • ✗

    DHCPv6 Guard is blocking DHCPv6 messages between hosts.

    Why it's wrong here

    DHCPv6 Guard filters server-to-client DHCPv6 messages on untrusted ports; it does not block host-to-host traffic, and these hosts may use static or SLAAC addresses anyway. It is the right control for stopping rogue DHCPv6 servers, not for inter-host reachability.

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

This 300-410 question is part of Courseiva's 1,401-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.