mediumMultiple ChoiceObjective-mapped
300-410 Practice Question: In IPv6 FHS, what is the default action for 'RA…
In IPv6 FHS, what is the default action for 'RA Guard' when a rogue RA is detected on a switch port?
⚠ Common exam trap
Cisco often tests the distinction between the default action (drop and syslog) and the more severe 'errdisable' action (shut down the port), leading candidates to mistakenly choose port shutdown as the default.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Drop the RA and generate a syslog message
In IPv6 First Hop Security (FHS), RA Guard is designed to block rogue Router Advertisement (RA) messages on switch ports. When a rogue RA is detected, the default action is to drop the offending packet and generate a syslog message, as specified by the 'drop' policy in the 'ipv6 nd raguard' configuration. This prevents unauthorized devices from advertising themselves as routers, mitigating man-in-the-middle attacks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Forward the RA to the CPU for inspection
Why it's wrong here
RA Guard does not forward the RA; it drops it by default.
- ✓
Drop the RA and generate a syslog message
Why this is correct
Correct. The default action is to drop the RA and log the event.
- ✗
Shut down the port
Why it's wrong here
Shutting down the port is not the default action; it is a possible manual configuration.
- ✗
Send a notification to the network management system
Why it's wrong here
This is not the default action; RA Guard only drops and logs by default.
Go deeper
Related to this question
About these practice questions
This 300-410 question is part of Courseiva's 1,966-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.