Courseiva
hardMultiple Choice

300-410 Practice Question: A network administrator configures 'ipv6 dhcp…

A network administrator configures 'ipv6 dhcp guard' on a switch and sets the policy to 'allow only' for a specific DHCPv6 server. However, clients are still receiving DHCPv6 replies from a rogue server on the same VLAN. The engineer verifies that the rogue server's port is not trusted. What is the most likely reason the rogue server's advertisements are not being blocked?

⚠ Common exam trap

Cisco often tests the prerequisite dependency between IPv6 snooping and DHCPv6 Guard, trapping candidates who assume that configuring the guard policy alone is sufficient to block rogue servers.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

IPv6 snooping is not enabled globally, so DHCPv6 Guard cannot inspect DHCPv6 messages.

DHCPv6 Guard relies on IPv6 snooping (also known as DHCPv6 snooping) to inspect DHCPv6 messages and enforce policies. If IPv6 snooping is not enabled globally on the switch, DHCPv6 Guard has no binding database or inspection mechanism to identify and block rogue DHCPv6 replies, even if the policy is configured and the rogue port is untrusted. The 'ipv6 dhcp guard' command alone is insufficient without the underlying snooping framework.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    IPv6 snooping is not enabled globally, so DHCPv6 Guard cannot inspect DHCPv6 messages.

    Why this is correct

    DHCPv6 Guard relies on IPv6 snooping to build the binding table and inspect messages; without it enabled globally, guard policies cannot classify or drop rogue DHCPv6 replies, so the untrusted port's advertisements pass through unchecked.

  • ✗

    The rogue server is using a different UDP port for DHCPv6.

    Why it's wrong here

    DHCPv6 operates solely over UDP ports 546 and 547; a rogue server using those same ports is still matched by the guard's message inspection. The option tempts because port-based filtering is common in ACL design, yet DHCPv6 Guard inspects message type and server address rather than relying on non-standard ports to evade it.

  • ✗

    The 'allow only' policy only works for DHCPv6 requests, not replies.

    Why it's wrong here

    DHCPv6 Guard filters both Solicit and Advertise messages, so the 'allow only' policy does apply to replies; the rogue server's Advertise would be dropped on an untrusted port. The option is tempting because guard does inspect request traffic, but the actual failure lies elsewhere, such as the policy being applied to the wrong VLAN or interface.

  • ✗

    The rogue server is on a trunk port, and DHCPv6 Guard does not apply to trunk ports.

    Why it's wrong here

    DHCPv6 Guard is configured on Layer 2 switch ports, including trunk ports, and trusts or blocks based on port configuration, so trunk membership does not exempt a rogue server. The option tempts because trunk ports carry multiple VLANs, but the guard's trust state on the receiving port is what determines filtering.

Visual reference

Client DHCP Server 1 Discover (broadcast) 2 Offer (IP: 192.168.1.10) 3 Request (I accept) 4 Acknowledge (lease confirmed) DORA — the four-step DHCP lease process

About these practice questions

This 300-410 question is part of Courseiva's 1,401-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.