nerdexam
Cisco

400-007 · Question #411

A company created an IPv6 adoption plan for its campus network that requires dual-stack connectivity on the network. Campus users must have IPv6 connectivity to an HR management application, which…

The correct answer is A. IPv6 RA guard B. IPv6 snooping. IPv6 RA guard: Protects the network from rogue IPv6 routers by filtering out unauthorized Router Advertisements (RAs), preventing attackers from masquerading as a legitimate IPv6 gateway. IPv6 snooping: Allows the network device to inspect and track IPv6 traffic, ensuring that…

Designing Security

Question

A company created an IPv6 adoption plan for its campus network that requires dual-stack connectivity on the network. Campus users must have IPv6 connectivity to an HR management application, which is the first IPv6-only application hosted in the company's data center. Which two security mechanisms can be used to prevent a malicious user from masquerading as the IPv6 gateway? (Choose two.)

Options

  • AIPv6 RA guard
  • BIPv6 snooping
  • CIPv6 device tracking
  • DIPv6 address glean
  • Eport ACLs

How the community answered

(25 responses)
  • A
    76% (19)
  • C
    8% (2)
  • D
    4% (1)
  • E
    12% (3)

Explanation

IPv6 RA guard: Protects the network from rogue IPv6 routers by filtering out unauthorized Router Advertisements (RAs), preventing attackers from masquerading as a legitimate IPv6 gateway. IPv6 snooping: Allows the network device to inspect and track IPv6 traffic, ensuring that only valid devices are communicating, and preventing rogue devices from impersonating the IPv6 gateway.

Topics

#IPv6 security#RA guard#IPv6 snooping#gateway spoofing

Community Discussion

No community discussion yet for this question.

Full 400-007 Practice