Cisco CCNP Security Core (SCOR) 350-701Network SecurityHard

A security auditor is reviewing the IPv6 deployment in a corporate network. They notice that stateless address autoconfiguration (SLAAC) is being used extensively. What is a significant security concern associated with SLAAC that the auditor should highlight, especially in environments requiring strict control over IP address assignment?

  1. AInability to assign DNS server information automatically.
  2. BDifficulty in tracking assigned IP addresses for auditing.
  3. CLack of DHCPv6 server for address assignment.
  4. DIncreased broadcast storm potential due to Neighbor Discovery Protocol.
Show answer & explanation

Correct answer: B. Difficulty in tracking assigned IP addresses for auditing.

A significant security concern with SLAAC is the difficulty in tracking assigned IPv6 addresses for auditing and inventory purposes. Since hosts generate their own addresses, there's no central record of which device has which address, making it harder to link network activity to a specific host or trace malicious activity. While SLAAC doesn't use DHCPv6 for address assignment, that's its design, not a concern. ND doesn't inherently increase broadcast storms. SLAAC can use Router Advertisements for DNS server info, or DHCPv6 can be used for 'other' configuration.

Why the other options are wrong

  • A. While SLAAC alone doesn't provide DNS server information, Router Advertisements can include DNS options, or DHCPv6 can be used in a stateless (for other config) mode alongside SLAAC to provide this.
  • C. The lack of a DHCPv6 server for address assignment is a characteristic of SLAAC, not a security concern in itself, as it's designed to be serverless.
  • D. Neighbor Discovery Protocol (NDP) is fundamental to IPv6 and does not inherently lead to increased broadcast storm potential; it uses multicast for efficiency.

SLAAC Auditing Challenge

Stateless Address Autoconfiguration (SLAAC) in IPv6 allows hosts to generate their own IP addresses, which can lead to challenges in centrally tracking and auditing assigned addresses for security and inventory management.

  • Hosts generate their own IP addresses.
  • No central record of IP assignments.
  • Complicates auditing and incident response.

Memory trick: IPv6 addresses are like snowflakes; how do you track them all?

More Network Security questions