Which IPv6 First Hop Security feature prevents rogue DHCPv6 servers from assigning addresses?

IT Exam Items Repository › Category: CCNP ENARSI v9 › Which IPv6 First Hop Security feature prevents rogue DHCPv6 servers from assigning addresses?

Which IPv6 First Hop Security feature prevents rogue DHCPv6 servers from assigning addresses?

  • RA Guard
  • ND Inspection
  • Source Guard
  • DHCPv6 Guard

Explanation: According to the sources, DHCPv6 Guard is a security feature designed to prevent rogue devices that are pretending to be legitimate DHCP servers from assigning improper or malicious IP information to clients. It functions by blocking DHCP reply and advertisement messages that originate from unauthorized servers or relay agents. The filtering decision is based on the device role (client, server, or relay) assigned to the receiving interface, effectively ensuring that only messages from authorized DHCP servers reach the clients, thereby mitigating risks like traffic redirection or denial of service (DoS) attacks.

Related exam: CCNP ENARSI v9 Course Final Exam