mediumMultiple Choice
300-410 Practice Question: Runs the following command on Router R1: R1# show…
A network engineer runs the following command on Router R1:
R1# show ipv6 dhcp guard policy Interface Policy Role State
Gi0/0/0 DHCP_GUARD server ACTIVE Gi0/0/1 DHCP_GUARD client ACTIVE Gi0/0/2 (default) client ACTIVE
Based on this output, which statement is correct?
⚠ Common exam trap
Cisco often tests the misconception that the 'client' role allows sending replies, when in fact only the 'server' role permits DHCPv6 server messages, and the 'client' role strictly blocks them.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Interface Gi0/0/0 is trusted to send DHCPv6 replies.
The output shows that interface Gi0/0/0 has the role 'server' and is ACTIVE under the DHCPv6 guard policy. In DHCPv6 guard, a port with the role 'server' is trusted to send DHCPv6 replies (advertise and reply messages), while ports with the role 'client' are blocked from sending such messages. Therefore, only Gi0/0/0 is allowed to send DHCPv6 replies.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Interface Gi0/0/0 is trusted to send DHCPv6 replies.
Why this is correct
Gi0/0/0 carries the server role, so DHCPv6 Guard permits it to forward server-originated Advertise and Reply messages; client-role interfaces have those dropped. This satisfies the stem's requirement to identify which interface is trusted for DHCPv6 replies.
- ✗
Interface Gi0/0/1 is trusted to send DHCPv6 replies.
Why it's wrong here
The client role blocks DHCPv6 replies arriving on Gi0/0/1; only the server role permits them. Trusting a client-facing port would let rogue servers answer. The server role is what authorises replies, so this option inverts the guard's direction.
- ✗
Interface Gi0/0/2 is trusted to send DHCPv6 replies.
Why it's wrong here
Gi0/0/2 shows the default client policy, which drops DHCPv6 replies; only the server role on Gi0/0/0 permits them. The client role exists to block rogue servers on access ports, so this interface is untrusted, not trusted.
- ✗
All interfaces are blocked from sending DHCPv6 replies.
Why it's wrong here
Gi0/0/0 carries the server role, so DHCPv6 replies are permitted there, not blocked everywhere. The client role on Gi0/0/1 and Gi0/0/2 does drop replies, but the blanket claim fails because one interface is explicitly trusted.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every 300-410 question from scratch — 1,401 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.