Which feature minimizes DoS attacks on an IPv6 network?
Which feature minimizes DoS attacks on an IPv6 network?
IPv6 Destination Guard helps in minimizing denial-of-service (DoS) attacks by filtering IPv6 traffic based on the destination address. It blocks Neighbor Discovery Protocol (NDP) resolution for destination addresses that are not found in the binding table, thus preventing traffic from reaching unknown destinations and reducing the risk of DoS attacks.
From Cisco: IPv6 - Destination Guard The Destination Guard feature helps in minimizing denial-of-service (DoS) attacks. It performs address resolutions only for those addresses that are active on the link, and requires the FHS binding table to be populated with the help of the IPv6 snooping feature. The feature enables the filtering of IPv6 traffic based on the destination address, and blocks the NDP resolution for destination addresses that are not found in the binding table. By default, the policy drops traffic coming for an unknown destination.
D is corerct
D correct: https://www.cisco.com/c/en/us/td/docs/routers/7600/ios/15S/configuration/guide/7600_15_0s_book/IPv6_Security.html#:~:text=on%20the%20VLAN.-,IPv6%20%2D%20Destination%20Guard,%2Dservice%20(DoS)%20attacks.
answer is correct -> https://www.cisco.com/c/en/us/td/docs/routers/7600/ios/15S/configuration/guide/7600_15_0s_book/IPv6_Security.html#86114