mediumMultiple Choice
300-410 Practice Question: Runs the following command to verify IPv6 device…
A network engineer runs the following command to verify IPv6 device tracking:
R1# show ipv6 device-tracking database Interface MAC Address VLAN IPv6 Address State Age Policy
Fa0/0 0011.2233.4455 10 2001:db8::1 ACTIVE 10 TRUSTED Fa0/0 00aa.bbcc.ddee 10 2001:db8::2 ACTIVE 5 INSPECT Fa0/0 1111.2222.3333 10 2001:db8::3 VERIFY 0 -
What does this output indicate?
⚠ Common exam trap
Cisco often tests the distinction between ACTIVE and VERIFY states in IPv6 device tracking, where candidates mistakenly assume all entries are stable (ACTIVE) or that VERIFY indicates a failure, rather than recognizing it as a normal transitional state during ND verification.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Device tracking shows two devices in ACTIVE state and one in VERIFY state, indicating ongoing ND verification for the third device.
The output shows three entries: two in ACTIVE state (indicating successful ND verification) and one in VERIFY state (meaning the device is currently undergoing Neighbor Discovery verification). The VERIFY state with age 0 indicates that the device has been recently discovered and is being validated before transitioning to ACTIVE. This confirms that device tracking is actively monitoring IPv6 devices, with ongoing ND verification for the third device.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Device tracking shows two devices in ACTIVE state and one in VERIFY state, indicating ongoing ND verification for the third device.
Why this is correct
The database lists three entries: two with policy TRUSTED and INSPECT in ACTIVE state, and one in VERIFY state with no policy, showing device tracking is still confirming reachability of the third device via ND.
- ✗
All devices are in ACTIVE state, indicating stable tracking.
Why it's wrong here
The database shows three entries with differing states: two ACTIVE and one VERIFY, so claiming all are ACTIVE misreads the output. It is tempting because ACTIVE entries dominate and suggest healthy tracking, but the VERIFY row indicates a binding still being validated rather than stable.
- ✗
Device tracking is disabled, and the database is empty.
Why it's wrong here
The database clearly contains three populated entries with MAC addresses, IPv6 addresses and policies, so tracking is running. It is tempting because an empty database would explain a lack of output, but here the presence of ACTIVE and VERIFY rows proves device tracking is enabled and learning bindings.
- ✗
Device tracking only tracks IPv4 addresses.
Why it's wrong here
Device tracking maintains both IPv4 and IPv6 bindings; the output lists IPv6 addresses such as 2001:db8::1, confirming IPv6 tracking. It is tempting because the command is often associated with IPv4 snooping, but the ipv6 keyword and displayed IPv6 addresses directly contradict an IPv4-only claim.
Visual reference
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
This 300-410 question is part of Courseiva's 1,401-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.