nerdexam
Cisco

300-410 · Question #48

Which statement about IPv6 inspection is true?

The correct answer is B. It learns and secures bindings for stateless autoconfiguration addresses in Layer 2 neighbor tables. IPv6 inspection learns and secures the bindings between stateless autoconfiguration IPv6 addresses and their corresponding Layer 2 MAC addresses. This process stores these mappings in the device's Layer 2 neighbor table, enhancing security against address spoofing.

Infrastructure Security

Question

Which statement about IPv6 inspection is true?

Exhibit

300-410 question #48 exhibit

Options

  • AIt learns and secures bindings for stateless autoconfiguration addresses in Layer 3 neighbor tables.
  • BIt learns and secures bindings for stateless autoconfiguration addresses in Layer 2 neighbor tables.
  • CIt learns and secures bindings for stateful autoconfiguration addresses in Layer 3 neighbor tables.
  • DIt learns and secures bindings for stateful autoconfiguration addresses in Layer 2 neighbor tables.

How the community answered

(17 responses)
  • B
    88% (15)
  • C
    6% (1)
  • D
    6% (1)

Why each option

IPv6 inspection learns and secures the bindings between stateless autoconfiguration IPv6 addresses and their corresponding Layer 2 MAC addresses. This process stores these mappings in the device's Layer 2 neighbor table, enhancing security against address spoofing.

AIt learns and secures bindings for stateless autoconfiguration addresses in Layer 3 neighbor tables.

IPv6 inspection for SLAAC primarily focuses on Layer 2 bindings (IPv6 to MAC address) rather than Layer 3 neighbor tables, which typically refer to routing table entries or next-hop information.

BIt learns and secures bindings for stateless autoconfiguration addresses in Layer 2 neighbor tables.Correct

IPv6 inspection, such as IPv6 Neighbor Discovery Inspection (NDI), is designed to validate and secure the IPv6 address-to-MAC address bindings, especially for addresses derived through Stateless Address Autoconfiguration (SLAAC). These bindings are critical for Layer 2 security and are stored in the device's Layer 2 neighbor table to ensure legitimate communication.

CIt learns and secures bindings for stateful autoconfiguration addresses in Layer 3 neighbor tables.

IPv6 inspection mechanisms like NDI are primarily concerned with securing stateless autoconfiguration (SLAAC) addresses, not stateful addresses which are typically assigned by a DHCPv6 server and have different security considerations.

DIt learns and secures bindings for stateful autoconfiguration addresses in Layer 2 neighbor tables.

IPv6 inspection secures stateless autoconfiguration (SLAAC) addresses, not stateful addresses, in Layer 2 neighbor tables.

Concept tested: IPv6 Neighbor Discovery Inspection

Source: https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst3850/software/release/3se/security/configuration_guide/b_sec_3se_3850_cg/b_sec_3se_3850_cg_chapter_0100.html

Topics

#IPv6 Inspection#Stateless Autoconfiguration#Neighbor Discovery Protocol#Binding Table Security

Community Discussion

No community discussion yet for this question.

Full 300-410 Practice