Which mitigation technique would prevent rogue servers from providing false IPv6 configuration parameters to clients?
- enabling DHCPv6 Guard
- enabling RA Guard
- implementing port security on edge ports
- disabling CDP on edge ports
Explanation: DHCPv6 Guard is a feature designed to ensure that rogue DHCPv6 servers are not able to hand out addresses to clients, redirect client traffic, or starve out the DHCPv6 server and cause a DoS attack. DHCPv6 Guard requires a policy to be configured in DHCP Guard configuration mode, and DHCPv6 Guard is enabled on an interface-by-interface basis.
Related exam: CCNP ENARSI 8 Modules 21 - 23 Checkpoint Exam: Infrastructure Security and Management Exam
Related exam: Switching, Routing, and Wireless Essentials (Version 7.00) - SRWE Final Exam Answers
Related exam: CCNP ENARSI v8 Certification Practice Exam
