Which IPv6 First Hop Security mechanism prevents a DoS attack on a host by exhausting its ability to do Layer 2 address resolution?

IT Exam Items Repository › Category: CCNP ENARSI v9 › Which IPv6 First Hop Security mechanism prevents a DoS attack on a host by exhausting its ability to do Layer 2 address resolution?

Which IPv6 First Hop Security mechanism prevents a DoS attack on a host by exhausting its ability to do Layer 2 address resolution?

  • IPv6 ND Inspection
  • IPv6 Source Guard
  • IPv6 RA Guard
  • DHCPv6 Guard

Explanation: IPv6 Source Guard is designed to prevent address spoofing that leads to Denial of Service (DoS) attacks on hosts. As described in the sources, without this protection, an attacker can generate packets from multiple bogus source addresses; a target server (host) will then exhaust its resources attempting Layer 2 address resolution (Neighbor Discovery) for these non-existent hosts, filling its neighbor table with incomplete entries and preventing it from processing legitimate traffic.

Related exam: Checkpoint Exam: MPLS and VPN Technologies