exam questions

Exam 300-410 All Questions

View all questions & answers for the 300-410 exam

Exam 300-410 topic 1 question 606 discussion

Actual exam question from Cisco's 300-410
Question #: 606
Topic #: 1
[All 300-410 Questions]

What is the use of IPv6 snooping?

  • A. captures IPv6 routing protocol packets to analyze
  • B. requires an external IPv6 packet analyzer
  • C. required for the operation of IPv6 RA Guard
  • D. captures any type of user traffic to create a binding table
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Brahim90
1 month, 3 weeks ago
Selected Answer: D
Given answer is correct per cisco book page 864. IPv6 Neighbor Discovery Inspection/IPv6 Snooping IPv6 neighbor discovery inspection/snooping is a feature that learns and populates the binding table for stateless autoconfiguration addresses. It analyzes ND (neighbor discovery) messages and places valid bindings in the binding table and drops all messages that do not have valid bindings. A valid ND message is one where the IPv6-to-MAC mapping can be verified.
upvoted 1 times
...
bk989
8 months, 1 week ago
A: Obviously it doesn't inspect OSPF packets. Any type of layer 3 pakets are DHCP packets. FALSE B:No it doesn't. This isn't the point of IPv6 snooping, it's for IPv6 security on the switch. C: According to the link I provided C is false (see below) D: By capturing any type of user traffic: ND packets, DHCP packets, and some data packets I guess this is the answer.
upvoted 2 times
bk989
8 months, 1 week ago
You also stated: “IPv6 Snooping is tightly integrated in the various IPv6 guard features (e.g. DHCPv6 guard and RA guard) as explained above.” While this is true in general you unfortunately just picked the two exceptions from this general rule: For DHCPv6 guard and RA guard this is not true, because both features are operating independent from IPv6 snooping and don’t rely on the binding table, which is only needed for other IPv6 FHS features like source guard, destination guard, IPv6 device tracking or optimization features like RA throttler or ND multicast suppress. https://insinuator.net/2014/01/configuring-ipv6-snooping-and-dhcpv6-guard-on-cisco-ios/#:~:text=This%20is%20the%20default%20option,Reply
upvoted 3 times
bk989
8 months, 1 week ago
The data traffic relates to destination guard: IPv6 Destination Guard 11. If an attacker attempts to spoof many IPv6 destinations in a short time, the router can get overwhelmed while trying to store temporary cache entries for each destination. The ______________feature blocks data traffic from an unknown source and filters IPv6 traffic based on the destination address. It populates all active destinations into the IPv6 first-hop security binding table, and it blocks data traffic when the destination is not identified. IPv6 Destination Guard https://quizlet.com/533167094/chapter-6-infrastructure-security-flash-cards/
upvoted 2 times
bk989
8 months, 1 week ago
so the answer is D
upvoted 2 times
...
...
...
...
[Removed]
9 months ago
Selected Answer: D
D is corerct
upvoted 1 times
...
[Removed]
9 months ago
Selected Answer: D
D is corerct
upvoted 1 times
...
amir_lotfy
9 months, 2 weeks ago
Selected Answer: C
IPv6 Snooping Enabled: IPv6 RA Guard relies on IPv6 snooping to inspect and filter IPv6 Router Advertisement (RA) messages received on Layer 2 interfaces. Therefore, IPv6 snooping must be enabled on the switch where RA Guard is configured.
upvoted 1 times
bk989
7 months, 4 weeks ago
no wrong
upvoted 1 times
...
...
Pietjeplukgeluk
9 months, 2 weeks ago
Selected Answer: D
D is wrong answer, but the best of all options as it does NOT capture "ANY" traffic, it only capture DHCPV6 traffic to create binding table entries
upvoted 2 times
bk989
8 months, 1 week ago
It captures DHCP, ND packets, and some data traffic (I believe the data traffic is related to source guard, and I'm not sure how this actually relates to populating the binding table)
upvoted 2 times
...
bk989
9 months, 1 week ago
Doesn't RA Guard rely on IPv6 Snooping? Why not C
upvoted 1 times
...
...
dapardo
10 months, 1 week ago
Selected Answer: D
Agree on TonyTe0 explanation
upvoted 2 times
...
TonyTe0
10 months, 1 week ago
D: correct IPv6 Snooping IPv6 snooping captures the IPv6 traffic and helps in populating the binding table. It gathers addresses in control messages such as Neighbor Discovery Protocol (NDP) or Dynamic Host Configuration Protocol (DHCP) packets. Depending on the security level, it blocks unwanted messages such as Router Advertisements (RA) or DHCP replies. This feature is a pre-requisite to the remaining security features mentioned here. https://www.cisco.com/c/en/us/td/docs/routers/7600/ios/15S/configuration/guide/7600_15_0s_book/IPv6_Security.html
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago