Courseiva
mediumMultiple Choice

300-410 Practice Question: Runs the following command on Router R1: R1# show…

A network engineer runs the following command on Router R1:

R1# show ipv6 nd raguard policy
Interface                      Policy                      Role            State

Gi0/0/0 RA_GUARD router ACTIVE Gi0/0/1 RA_GUARD host ACTIVE Gi0/0/2 (default) host ACTIVE

Based on this output, which statement is correct?

⚠ Common exam trap

Cisco often tests the misconception that all interfaces with an active RA Guard policy are blocked, but the key differentiator is the 'role' (router vs. host), not just the policy being active.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Interface Gi0/0/0 is allowed to send Router Advertisements.

The 'show ipv6 nd raguard policy' output shows that interface Gi0/0/0 is configured with the RA_GUARD policy in the 'router' role and is ACTIVE. In IPv6 RA Guard, a port in the 'router' role is explicitly permitted to send Router Advertisements (RAs), while ports in the 'host' role are blocked from sending RAs. Therefore, only Gi0/0/0 is allowed to send RAs, making option A correct.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Interface Gi0/0/0 is allowed to send Router Advertisements.

    Why this is correct

    Gi0/0/0 is configured with the router role, so RA guard permits Router Advertisement and redirect messages to ingress there. The host role on Gi0/0/1 and the default host policy on Gi0/0/2 block RAs, satisfying the requirement that only the uplink-facing interface accepts advertisements from the legitimate router.

  • ✗

    Interface Gi0/0/1 is allowed to send Router Advertisements.

    Why it's wrong here

    RA guard in host role drops inbound Router Advertisements, so Gi0/0/1 cannot send them despite the policy being active. The router role permits RAs, which is why Gi0/0/0 is the sending interface; host mode exists to block rogue advertisements from end devices.

  • ✗

    Interface Gi0/0/2 is allowed to send Router Advertisements.

    Why it's wrong here

    The (default) policy assigns the host role, which drops Router Advertisement and Router Solicitation messages received on Gi0/0/2. RA guard is designed so that only explicitly trusted router-facing ports, such as Gi0/0/0, may originate advertisements.

  • ✗

    All interfaces are blocked from sending Router Advertisements.

    Why it's wrong here

    RA guard blocks Router Advertisements only on interfaces configured with the host role, so Gi0/0/0, set to router, still forwards them. The tempting reading treats the policy name as globally blocking, yet RA guard exists precisely to permit legitimate routers on uplinks while filtering rogue RAs from access ports.

About these practice questions

One of 1,401 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.