Courseiva
mediumMultiple Choice

300-410 Practice Question: Runs the following command to verify IPv6 binding…

A network engineer runs the following command to verify IPv6 binding table:

R1# show ipv6 neighbors binding

IPv6 Address Age Link-layer Addr State Interface VLAN Policy 2001:db8::1 10 0011.2233.4455 REACH Fa0/1 10 TRUSTED 2001:db8::2 5 00aa.bbcc.ddee STALE Fa0/0 10 INSPECT 2001:db8::3 0 1111.2222.3333 INCOMP Fa0/0 10 -

What does this output indicate?

⚠ Common exam trap

Cisco often tests the misinterpretation of the 'show ipv6 neighbors binding' output by confusing it with 'show ipv6 neighbors' (which shows the ND cache), leading candidates to overlook the FHS-specific policy column and state meanings, especially the significance of INCOMP and STALE states in security contexts.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The binding table shows three entries: one reachable on trusted port, one stale on untrusted port, and one incomplete, indicating active ND learning.

The output of 'show ipv6 neighbors binding' displays the IPv6 binding table used in First Hop Security (FHS) features like IPv6 Snooping. The entry for 2001:db8::1 has a REACH state on interface Fa0/1 with a TRUSTED policy, indicating it is reachable on a trusted port. The entry for 2001:db8::2 is STALE on Fa0/0 with an INSPECT policy, meaning it is on an untrusted port and requires verification. The entry for 2001:db8::3 is INCOMP (incomplete) on Fa0/0, showing an ongoing Neighbor Discovery (ND) process where the link-layer address has not yet been resolved.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The binding table shows three entries: one reachable on trusted port, one stale on untrusted port, and one incomplete, indicating active ND learning.

    Why this is correct

    The binding table confirms IPv6 first-hop security is learning neighbour bindings across VLAN 10. The REACH entry on Fa0/1 carries TRUSTED policy, the STALE entry on Fa0/0 carries INSPECT, and the INCOMP entry shows an unresolved neighbour discovery attempt — satisfying the requirement to verify live ND learning states.

  • ✗

    The binding table is empty, indicating no ND activity.

    Why it's wrong here

    The output lists three populated rows with IPv6 addresses, link-layer addresses and states, so the table is clearly not empty. It is tempting because an empty binding table would explain absent ND activity, but here REACH, STALE and INCOMP entries prove active neighbour discovery and snooping.

  • ✗

    The binding table shows all entries as reachable, indicating stable neighbor relationships.

    Why it's wrong here

    Only the first entry shows REACH; the others are STALE and INCOMP, so neighbour relationships are not uniformly stable. Treating all rows as reachable is tempting when scanning the table quickly, yet the State column explicitly distinguishes reachability from staleness and incomplete resolution.

  • ✗

    The binding table is only for DHCPv6-learned addresses.

    Why it's wrong here

    Entries here include a link-local-derived binding with no DHCPv6 exchange shown, and the Policy column reflects First-Hop Security snooping rather than DHCPv6 lease learning. It is tempting because DHCPv6 snooping also populates bindings, but this table is the IPv6 neighbour binding table covering ND-derived entries.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every 300-410 question from scratch — 1,401 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.