mediumMultiple Choice
300-410 Practice Question: Runs the following command to verify IPv6 ND…
A network engineer runs the following command to verify IPv6 ND inspection policy:
R1# show ipv6 nd inspection policy INSPECT
Policy: INSPECT Status: Active Device role: node Trusted ports: none Untrusted ports: Fa0/0 ND inspection: enabled Validation: - Source MAC address: verify - Destination MAC address: verify - IPv6 source address: verify - IPv6 destination address: verify - Nonce: disabled - Timestamp: disabled
What does this output indicate?
⚠ Common exam trap
Cisco often tests the distinction between trusted and untrusted ports in IPv6 ND inspection, where candidates may mistakenly think validation occurs on trusted ports or that the policy is inactive when it is actually active on untrusted ports.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The policy INSPECT validates source and destination MAC and IPv6 addresses on untrusted port Fa0/0.
The output shows that the policy INSPECT is active, with ND inspection enabled and validation configured for source MAC, destination MAC, IPv6 source, and IPv6 destination addresses. The 'Untrusted ports: Fa0/0' indicates that these validations are applied to that untrusted port, which is the standard behavior for IPv6 ND inspection to prevent spoofing attacks on untrusted interfaces.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The policy INSPECT validates source and destination MAC and IPv6 addresses on untrusted port Fa0/0.
Why this is correct
The output confirms that policy INSPECT is active and enforces validation of source and destination MAC addresses alongside IPv6 source and destination addresses. Because Fa0/0 is untrusted, all four checks apply to traffic arriving there, satisfying the requirement to verify ND packets on that interface.
- ✗
The policy INSPECT only validates source MAC addresses on trusted ports.
Why it's wrong here
The output lists four validation checks — source and destination MAC, plus IPv6 source and destination address — all set to verify, and shows no trusted ports configured. It is tempting because MAC validation is enabled, but the policy verifies far more than source MAC and applies to the untrusted Fa0/0 port.
- ✗
The policy INSPECT disables ND inspection and logs all ND messages.
Why it's wrong here
The output states 'ND inspection: enabled' and 'Status: Active', so inspection is running, not disabled, and no logging action is shown. It is tempting because untrusted ports and disabled nonce/timestamp checks suggest restricted behaviour, but these are validation settings, not a logging or disable function.
- ✗
The policy INSPECT is inactive and not applied to any interface.
Why it's wrong here
The policy shows 'Status: Active' and 'ND inspection: enabled', with Fa0/0 listed as an untrusted port, proving it is applied. It is tempting because 'Trusted ports: none' can read as no ports configured, but that field concerns trust state, not whether the policy is bound to an interface.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
One of 1,401 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.