Exam 300-410 All QuestionsBrowse all questions from this exam
Question 149

What are two functions of IPv6 Source Guard? (Choose two.)

    Correct Answer: B, C

    IPv6 Source Guard is a security feature that filters traffic based on the IPv6 binding table to ensure that only legitimate traffic passes through. It denies traffic from unknown sources or unallocated addresses which are not stored in the binding table. This is achieved by populating the binding table with legitimate entries, often from DHCP or Neighbor Discovery mechanisms. Using this binding table, IPv6 Source Guard allows only legitimate traffic, thereby mitigating potential security threats from unauthorized sources.

Discussion
BrandOptions: BC

First of all the question asks to choose two. Second of all, as the name indicates the Source Guard feature determines if the source of a traffic is coming from a prefix or address in the binding table. Binding table entries are populated using mechanisms like ND. So saying "It works independent from IPv6 neighbor discovery." is WRONG. So "one" of the two correct answers can not be A.

GreatDaneOptions: BC

Ref: IPv6 Source Guard and Prefix Guard – Cisco “… Information About IPv6 Source Guard and Prefix Guard IPv6 Source Guard Overview IPv6 source guard is an interface feature between the populated binding table and data traffic filtering. This feature enables the device to deny traffic when it is originated from an address that is not stored in the binding table. … IPv6 source guard can deny traffic from unknown sources or unallocated addresses, such as traffic from sources not assigned by a DHCP server. …” A. It works independent from IPv6 neighbor discovery. Wrong answer. B. It denies traffic from unknown sources or unallocated addresses. Correct answer. C. It uses the populated binding table to allow legitimate traffic. Correct answer. D. It denies traffic by inspecting neighbor discovery packets for specific patterns. Wrong answer. E. It blocks certain traffic by inspecting DHCP packets for specific sources. Wrong answer.

examSharkOptions: BC

The given answer is correct IPv6 Source Guard blocks any data traffic from an unknown source. For example, one that is not already populated in the binding table or previously learned through Neighbor Discovery (ND) or Dynamic Host Configuration Protocol (DHCP) gleaning.

leecharxos

yeap :It filters inbound traffic on L2 switch ports that are not in the IPv6 binding table, https://networklessons.com/cisco/ccie-routing-switching-written/ipv6-source-guard

chris110Options: BC

B. It denies traffic from unknown sources or unallocated addresses. C. It uses the populated binding table to allow legitimate traffic.

2581c6aOptions: BC

BC are correct

SeMo0o0o0Options: BC

B & C are correct

conftOption: A

the given answer is correct.

SeMo0o0o0

if so why would you mess up the votes?