200-301 exam dumps

200-301 practice question 438 of 506

Cisco Certified Network Associate. Free level, Cisco. Free question with the correct answer and a full explanation.

200-301 Question 438

Select 3

You are tasked with securing a Layer 2 network against common attacks. The network includes a mix of trusted and untrusted devices connected to a switch. DHCP spoofing and ARP poisoning attacks are a concern. Which configurations are necessary to ensure the switch mitigates these threats effectively?

  1. A

    Enable DHCP snooping and define trusted ports.

  2. B

    Configure dynamic ARP inspection and enable it globally.

  3. C

    Enable port security and assign static MAC addresses to all ports.

  4. D

    Enable DHCP snooping, and configure the switch to drop packets from untrusted ports.

  5. E

    Configure VLAN access control lists (VACLs) to block ARP traffic.

Show answer and explanation

Correct answers: A, B, D

Explanation

To secure a Layer 2 network against DHCP spoofing and ARP poisoning, you must enable and properly configure DHCP snooping and dynamic ARP inspection (DAI). DHCP snooping ensures only legitimate DHCP servers are allowed to operate by designating trusted ports and dropping malicious DHCP traffic on untrusted ports. DAI leverages the DHCP snooping binding table to validate ARP packets, thus mitigating ARP poisoning attacks. While port security and VACLs have their uses, they do not directly address these specific Layer 2 security threats.

  • A. Correct.

    Correct: DHCP snooping is a critical feature that prevents DHCP spoofing attacks by validating DHCP messages and defining trusted ports for legitimate DHCP servers.

  • B. Correct.

    Correct: Dynamic ARP Inspection (DAI) works in conjunction with DHCP snooping to prevent ARP poisoning by verifying ARP packets against the DHCP snooping binding table.

  • C. Incorrect.

    Incorrect: While port security can help limit access to specific MAC addresses, it does not directly address DHCP spoofing or ARP poisoning attacks.

  • D. Correct.

    Correct: DHCP snooping must be configured to drop packets from untrusted ports to prevent unauthorized devices from injecting malicious DHCP messages.

  • E. Incorrect.

    Incorrect: VLAN access control lists (VACLs) are not specifically designed to block ARP traffic or mitigate DHCP spoofing; they are used for broader traffic filtering purposes.

Timed practice exam

Take a 200-301 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam