200-301 exam dumps

200-301 practice question 441 of 506

Cisco Certified Network Associate. Free level, Cisco. Free question with the correct answer and a full explanation.

200-301 Question 441

Select 3

You are tasked with configuring Layer 2 security features on a switch to mitigate potential attacks. The network administrator asks you to prevent rogue DHCP servers from assigning IP addresses while ensuring ARP traffic is validated against the DHCP snooping binding table. Which configuration steps should you implement?

  1. A

    Enable DHCP snooping on the switch and configure trusted ports for legitimate DHCP servers

  2. B

    Enable dynamic ARP inspection (DAI) on the switch and configure trusted ports for legitimate devices

  3. C

    Disable DHCP snooping on the switch to allow ARP inspection to function independently

  4. D

    Configure a static ARP table entry for all devices in the network to prevent ARP spoofing

  5. E

    Ensure DHCP snooping is enabled on VLANs where ARP inspection is required

Show answer and explanation

Correct answers: A, B, E

Explanation

To mitigate attacks like rogue DHCP servers and ARP spoofing, DHCP snooping and dynamic ARP inspection (DAI) must be enabled. DHCP snooping prevents unauthorized DHCP servers from assigning IP addresses and creates a binding table of IP-to-MAC mappings. Dynamic ARP inspection uses this binding table to validate ARP packets. Trusted ports must be configured for legitimate devices and DHCP servers. Additionally, DHCP snooping must be enabled for VLANs where DAI is applied, as DAI relies on the DHCP snooping binding table.

  • A. Correct.

    Correct. Enabling DHCP snooping and configuring trusted ports ensures that rogue DHCP servers cannot assign IP addresses. This is a foundational step for protecting the network.

  • B. Correct.

    Correct. Enabling DAI and configuring trusted ports ensures that ARP traffic is validated against the DHCP snooping binding table, mitigating ARP spoofing attacks.

  • C. Incorrect.

    Incorrect. DHCP snooping must be enabled for dynamic ARP inspection to function properly since DAI relies on the DHCP snooping binding table.

  • D. Incorrect.

    Incorrect. Configuring static ARP table entries is impractical for large networks and does not leverage the dynamic protection provided by DHCP snooping and ARP inspection.

  • E. Correct.

    Correct. DAI relies on the DHCP snooping binding table, which means DHCP snooping must be enabled on the VLANs where DAI is applied.

Timed practice exam

Take a 200-301 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam