300-420 exam dumps

300-420 practice question 107 of 323

Designing Cisco Enterprise Networks. Professional level, Cisco. Free question with the correct answer and a full explanation.

300-420 Question 107

Select 3

An enterprise network engineer is tasked with securing Layer 2 of the network to prevent attacks such as MAC address flooding, rogue switches, and unauthorized access to VLANs. Which combination of Layer 2 security techniques should the engineer implement to mitigate these threats?

  1. A

    Enable BPDU Guard on edge ports to protect against rogue switches.

  2. B

    Configure Port Security to limit the number of MAC addresses per port.

  3. C

    Disable STP on all ports to prevent spanning-tree manipulation attacks.

  4. D

    Apply a VLAN Access Control List (VACL) to restrict traffic within VLANs.

  5. E

    Enable Dynamic ARP Inspection (DAI) to mitigate ARP spoofing attacks.

Show answer and explanation

Correct answers: A, B, D

Explanation

To secure Layer 2, BPDU Guard protects against rogue switches by shutting down edge ports receiving unexpected BPDUs. Port Security mitigates MAC flooding by restricting the number of allowed MAC addresses per port. VLAN Access Control Lists (VACLs) provide traffic filtering within VLANs to prevent unauthorized communication. These techniques collectively address the threats described in the scenario, while disabling STP or enabling unrelated features like DAI are not appropriate solutions for this specific case.

  • A. Correct.

    BPDU Guard ensures that edge ports (configured as PortFast) shut down if they receive unexpected Bridge Protocol Data Units (BPDUs), protecting against rogue switches and unauthorized STP manipulation.

  • B. Correct.

    Port Security limits the number of allowable MAC addresses on a port, helping to mitigate MAC address flooding attacks and other unauthorized access attempts.

  • C. Incorrect.

    Disabling STP entirely is not recommended as it increases the risk of Layer 2 loops, which can cause severe network outages. Instead, STP security features like BPDU Guard should be used.

  • D. Correct.

    VLAN Access Control Lists (VACLs) are used to filter traffic within VLANs, providing an additional layer of security to control unauthorized communication.

  • E. Incorrect.

    Dynamic ARP Inspection (DAI) is effective for preventing ARP spoofing attacks, but it is not directly related to the threats mentioned in the scenario (MAC flooding, rogue switches, and VLAN access control).

Timed practice exam

Take a 300-420 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam