hardMultiple ChoiceObjective-mapped
300-410 Practice Question: A network administrator configures 'ipv6 dhcp…
A network administrator configures 'ipv6 dhcp guard' on a switch and sets the policy to 'allow only' for a specific DHCPv6 server. However, clients are still receiving DHCPv6 replies from a rogue server on the same VLAN. The engineer verifies that the rogue server's port is not trusted. What is the most likely reason the rogue server's advertisements are not being blocked?
⚠ Common exam trap
Cisco often tests the prerequisite dependency between IPv6 snooping and DHCPv6 Guard, trapping candidates who assume that configuring the guard policy alone is sufficient to block rogue servers.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
IPv6 snooping is not enabled globally, so DHCPv6 Guard cannot inspect DHCPv6 messages.
DHCPv6 Guard relies on IPv6 snooping (also known as DHCPv6 snooping) to inspect DHCPv6 messages and enforce policies. If IPv6 snooping is not enabled globally on the switch, DHCPv6 Guard has no binding database or inspection mechanism to identify and block rogue DHCPv6 replies, even if the policy is configured and the rogue port is untrusted. The 'ipv6 dhcp guard' command alone is insufficient without the underlying snooping framework.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
IPv6 snooping is not enabled globally, so DHCPv6 Guard cannot inspect DHCPv6 messages.
Why this is correct
DHCPv6 Guard depends on IPv6 snooping for packet inspection.
- ✗
The rogue server is using a different UDP port for DHCPv6.
Why it's wrong here
DHCPv6 uses well-known ports 546 and 547.
- ✗
The 'allow only' policy only works for DHCPv6 requests, not replies.
Why it's wrong here
It works for both.
- ✗
The rogue server is on a trunk port, and DHCPv6 Guard does not apply to trunk ports.
Why it's wrong here
It applies to all ports.
Visual reference
Go deeper
Related to this question
About these practice questions
This 300-410 question is part of Courseiva's 1,966-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.