200-301 exam dumps

200-301 practice question 439 of 506

Cisco Certified Network Associate. Free level, Cisco. Free question with the correct answer and a full explanation.

200-301 Question 439

Select 2

You are configuring Layer 2 security on a switch in a network with multiple VLANs. The goal is to prevent rogue DHCP servers from assigning IP addresses to clients and to block malicious ARP replies from being sent to hosts. Which combination of configurations should you apply?

  1. A

    Enable DHCP snooping on the switch and configure trusted interfaces for legitimate DHCP servers.

  2. B

    Enable dynamic ARP inspection and configure ARP ACLs to validate ARP packets.

  3. C

    Configure port security on all access ports to restrict the number of MAC addresses allowed.

  4. D

    Enable storm control on all interfaces to limit broadcast traffic.

  5. E

    Disable DTP (Dynamic Trunking Protocol) on trunk ports to prevent VLAN hopping.

Show answer and explanation

Correct answers: A, B

Explanation

To enhance Layer 2 security and protect against rogue DHCP servers and ARP spoofing, enabling DHCP snooping and dynamic ARP inspection is critical. DHCP snooping prevents unauthorized DHCP servers from assigning IP addresses, while DAI validates ARP packets to ensure they are not malicious. These configurations work together to secure the network at Layer 2.

  • A. Correct.

    Correct: Enabling DHCP snooping and designating trusted interfaces ensures that only legitimate DHCP servers can assign IP addresses, protecting against rogue servers.

  • B. Correct.

    Correct: Dynamic ARP Inspection (DAI) verifies ARP packets against the DHCP snooping database or ARP ACLs, mitigating ARP spoofing attacks.

  • C. Incorrect.

    Incorrect: While port security enhances Layer 2 security, it does not directly address DHCP or ARP-related threats.

  • D. Incorrect.

    Incorrect: Storm control is useful for managing broadcast storms but is unrelated to DHCP snooping or ARP inspection.

  • E. Incorrect.

    Incorrect: Disabling DTP can prevent VLAN hopping attacks but does not mitigate threats from rogue DHCP servers or ARP spoofing.

Timed practice exam

Take a 200-301 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam