nerdexam
Cisco

300-360 · Question #154

You must configure IPV6 to drop unwanted or rogue RA packets that come from wireless clients. Which feature do you enable?

The correct answer is D. RA guard. RA Guard (Router Advertisement Guard) is a Layer 2 security feature that inspects ICMPv6 Router Advertisement messages and drops any RA packets sourced from unauthorized devices - such as rogue wireless clients attempting to spoof a default gateway. DHCPv6 Server Guard blocks…

WLAN Security

Question

You must configure IPV6 to drop unwanted or rogue RA packets that come from wireless clients. Which feature do you enable?

Options

  • ADHCPv6 Server Guard
  • BIPv6 Source Guard
  • CRA throttling
  • DRA guard

How the community answered

(53 responses)
  • A
    8% (4)
  • B
    2% (1)
  • C
    4% (2)
  • D
    87% (46)

Explanation

RA Guard (Router Advertisement Guard) is a Layer 2 security feature that inspects ICMPv6 Router Advertisement messages and drops any RA packets sourced from unauthorized devices - such as rogue wireless clients attempting to spoof a default gateway. DHCPv6 Server Guard blocks unauthorized DHCPv6 servers but does not address RA packets. IPv6 Source Guard validates IPv6 source addresses against a binding table. RA Throttling limits the rate of RA forwarding but does not block rogue RAs. Only RA Guard specifically enforces which ports are permitted to send RA messages.

Topics

#IPv6#RA guard#rogue RA packets#wireless security

Community Discussion

No community discussion yet for this question.

Full 300-360 Practice