Courseiva
mediumMultiple ChoiceObjective-mapped

300-410 Practice Question: Runs the following command to verify IPv6 ND…

A network engineer runs the following command to verify IPv6 ND inspection policy:

R1# show ipv6 nd inspection policy INSPECT

Policy: INSPECT Status: Active Device role: node Trusted ports: none Untrusted ports: Fa0/0 ND inspection: enabled Validation: - Source MAC address: verify - Destination MAC address: verify - IPv6 source address: verify - IPv6 destination address: verify - Nonce: disabled - Timestamp: disabled

What does this output indicate?

⚠ Common exam trap

Cisco often tests the distinction between trusted and untrusted ports in IPv6 ND inspection, where candidates may mistakenly think validation occurs on trusted ports or that the policy is inactive when it is actually active on untrusted ports.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The policy INSPECT validates source and destination MAC and IPv6 addresses on untrusted port Fa0/0.

The output shows that the policy INSPECT is active, with ND inspection enabled and validation configured for source MAC, destination MAC, IPv6 source, and IPv6 destination addresses. The 'Untrusted ports: Fa0/0' indicates that these validations are applied to that untrusted port, which is the standard behavior for IPv6 ND inspection to prevent spoofing attacks on untrusted interfaces.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The policy INSPECT validates source and destination MAC and IPv6 addresses on untrusted port Fa0/0.

    Why this is correct

    All four validation checks are enabled, and the port is untrusted.

  • The policy INSPECT only validates source MAC addresses on trusted ports.

    Why it's wrong here

    The port is untrusted, not trusted, and multiple validations are enabled.

  • The policy INSPECT disables ND inspection and logs all ND messages.

    Why it's wrong here

    ND inspection is enabled, not disabled.

  • The policy INSPECT is inactive and not applied to any interface.

    Why it's wrong here

    Status is Active, and Fa0/0 is listed as an untrusted port.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

One of 1,966 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.