Courseiva
mediumMultiple Choice

300-410 Practice Question: Is troubleshooting an issue where IPv6 traffic…

A network engineer is troubleshooting an issue where IPv6 traffic from a host is being dropped by the switch. The switch has IPv6 Source Guard enabled. The host has a static IPv6 address 2001:db8:2::20. The engineer sees that the binding table does not contain an entry for this host. What should the engineer do to resolve the issue without disabling IPv6 Source Guard?

⚠ Common exam trap

Cisco often tests the distinction between the IPv6 neighbor cache (Layer 2 mapping) and the IPv6 binding table (used by First Hop Security features), leading candidates to mistakenly choose the 'ipv6 neighbor' command as a solution for Source Guard bindings.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable IPv6 ND snooping on the VLAN to allow the switch to learn the host's binding from Neighbor Discovery messages.

IPv6 Source Guard relies on the IPv6 binding table to validate traffic. When a host uses a static IPv6 address, the switch cannot learn the binding via DHCPv6 snooping. Enabling IPv6 ND snooping on the VLAN allows the switch to inspect Neighbor Discovery (ND) messages (RFC 4861) and dynamically populate the binding table with the host's IPv6 address and MAC address, thus permitting the traffic without disabling Source Guard.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable IPv6 ND snooping on the VLAN to allow the switch to learn the host's binding from Neighbor Discovery messages.

    Why this is correct

    IPv6 Source Guard validates source addresses against the binding table, which is empty for this static host. Enabling IPv6 ND snooping lets the switch populate that table from Neighbor Discovery messages, restoring forwarding while keeping Source Guard active.

  • ✗

    Configure the host to use DHCPv6 to obtain an address so that the binding is learned via DHCPv6 snooping.

    Why it's wrong here

    The host already holds a static address, so DHCPv6 snooping cannot populate a binding for 2001:db8:2::20; the address would change. DHCPv6 snooping suits hosts configured to obtain addresses dynamically rather than manually assigned static ones.

  • ✗

    Add a static binding entry for the host in the IPv6 binding table using the 'ipv6 neighbor' command.

    Why it's wrong here

    'ipv6 neighbor' populates the neighbour cache, not the IPv6 Source Guard binding table, so the drop persists. That command is correct for resolving link-layer address mappings, not for authorising a static address against source guard.

  • ✗

    Disable IPv6 Source Guard on the port connected to the host.

    Why it's wrong here

    Disabling IPv6 Source Guard removes the filtering that drops the traffic, but the stem explicitly requires resolution without disabling it. The feature exists to validate source addresses against the binding table, so it would be the right approach only where that verification is genuinely unwanted, not where a missing binding entry simply needs creating.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

Courseiva writes every 300-410 question from scratch — 1,401 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.