hardMultiple Choice
300-410 Practice Question: A network administrator configures 'ipv6 dhcp…
A network administrator configures 'ipv6 dhcp guard' on a switch and sets the policy to 'allow only' for a specific DHCPv6 server. However, clients are still receiving DHCPv6 replies from a rogue server on the same VLAN. The engineer verifies that the rogue server's port is not trusted. What is the most likely reason the rogue server's advertisements are not being blocked?
⚠ Common exam trap
Cisco often tests the prerequisite dependency between IPv6 snooping and DHCPv6 Guard, trapping candidates who assume that configuring the guard policy alone is sufficient to block rogue servers.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
IPv6 snooping is not enabled globally, so DHCPv6 Guard cannot inspect DHCPv6 messages.
DHCPv6 Guard relies on IPv6 snooping (also known as DHCPv6 snooping) to inspect DHCPv6 messages and enforce policies. If IPv6 snooping is not enabled globally on the switch, DHCPv6 Guard has no binding database or inspection mechanism to identify and block rogue DHCPv6 replies, even if the policy is configured and the rogue port is untrusted. The 'ipv6 dhcp guard' command alone is insufficient without the underlying snooping framework.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
IPv6 snooping is not enabled globally, so DHCPv6 Guard cannot inspect DHCPv6 messages.
Why this is correct
DHCPv6 Guard relies on IPv6 snooping to build the binding table and inspect messages; without it enabled globally, guard policies cannot classify or drop rogue DHCPv6 replies, so the untrusted port's advertisements pass through unchecked.
- ✗
The rogue server is using a different UDP port for DHCPv6.
Why it's wrong here
DHCPv6 operates solely over UDP ports 546 and 547; a rogue server using those same ports is still matched by the guard's message inspection. The option tempts because port-based filtering is common in ACL design, yet DHCPv6 Guard inspects message type and server address rather than relying on non-standard ports to evade it.
- ✗
The 'allow only' policy only works for DHCPv6 requests, not replies.
Why it's wrong here
DHCPv6 Guard filters both Solicit and Advertise messages, so the 'allow only' policy does apply to replies; the rogue server's Advertise would be dropped on an untrusted port. The option is tempting because guard does inspect request traffic, but the actual failure lies elsewhere, such as the policy being applied to the wrong VLAN or interface.
- ✗
The rogue server is on a trunk port, and DHCPv6 Guard does not apply to trunk ports.
Why it's wrong here
DHCPv6 Guard is configured on Layer 2 switch ports, including trunk ports, and trusts or blocks based on port configuration, so trunk membership does not exempt a rogue server. The option tempts because trunk ports carry multiple VLANs, but the guard's trust state on the receiving port is what determines filtering.
Visual reference
Go deeper
Related to this question
About these practice questions
This 300-410 question is part of Courseiva's 1,401-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.