nerdexam
Cisco

300-410 · Question #80

What is a function of IPv6 ND inspection?

The correct answer is B. It learns and secures bindings for stateful autoconfiguration addresses in Layer 2 neighbor tables. IPv6 Neighbor Discovery (ND) inspection is a security feature that learns and secures IPv6 address-to-MAC address bindings for stateless autoconfiguration in Layer 2 neighbor tables.

Infrastructure Security

Question

What is a function of IPv6 ND inspection?

Exhibit

300-410 question #80 exhibit

Options

  • AIt learns and secures bindings for stateless autoconfiguration addresses in Layer 3 neighbor tables
  • BIt learns and secures bindings for stateful autoconfiguration addresses in Layer 2 neighbor tables.
  • CIt learns and secures bindings for stateful autoconfiguration addresses in Layer 3 neighbor tables.
  • DIt learns and secures bindings for stateful autoconfiguration addresses in Layer 2 neighbor tables.

How the community answered

(35 responses)
  • A
    3% (1)
  • B
    94% (33)
  • C
    3% (1)

Why each option

IPv6 Neighbor Discovery (ND) inspection is a security feature that learns and secures IPv6 address-to-MAC address bindings for stateless autoconfiguration in Layer 2 neighbor tables.

AIt learns and secures bindings for stateless autoconfiguration addresses in Layer 3 neighbor tables

ND inspection secures Layer 2 (MAC) bindings for IPv6 addresses in neighbor tables, not Layer 3 neighbor tables in the context of binding security.

BIt learns and secures bindings for stateful autoconfiguration addresses in Layer 2 neighbor tables.Correct

IPv6 ND inspection monitors Neighbor Discovery messages to build and secure a binding table that maps stateless autoconfiguration (SLAAC) IPv6 addresses to their corresponding Layer 2 (MAC) addresses. This mechanism prevents common ND-based attacks like address spoofing by verifying the integrity of neighbor bindings.

CIt learns and secures bindings for stateful autoconfiguration addresses in Layer 3 neighbor tables.

ND inspection primarily focuses on securing bindings for *stateless* autoconfiguration (SLAAC) addresses, not stateful autoconfiguration which is handled by DHCPv6.

DIt learns and secures bindings for stateful autoconfiguration addresses in Layer 2 neighbor tables.

ND inspection primarily focuses on securing bindings for *stateless* autoconfiguration (SLAAC) addresses, not stateful autoconfiguration, even though it does operate at Layer 2.

Concept tested: IPv6 Neighbor Discovery (ND) inspection

Source: https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst3750x_3560x/software/release/12-2_55_se/configuration/guide/3750x_3560x_cg/swipv6.html

Topics

#IPv6 ND Inspection#Neighbor Discovery Protocol#IPv6 Security#Binding Table

Community Discussion

No community discussion yet for this question.

Full 300-410 Practice