300-440 exam dumps

300-440 practice question 199 of 293

Designing and Implementing Cloud Connectivity. Professional level, Cisco. Free question with the correct answer and a full explanation.

300-440 Question 199

Select 2

You are configuring infrastructure security for a Cisco Enterprise network. The network requires protection against unauthorized devices connecting to switch ports, as well as mitigation of MAC address table exhaustion attacks. Which Cisco switch security feature(s) should you implement to meet these requirements?

  1. A

    Port Security

  2. B

    802.1X Authentication

  3. C

    Dynamic ARP Inspection (DAI)

  4. D

    IP Source Guard

  5. E

    DHCP Snooping

Show answer and explanation

Correct answers: A, B

Explanation

To address the requirements of preventing unauthorized device connections and mitigating MAC address table exhaustion attacks, Port Security and 802.1X Authentication are the most suitable features. Port Security directly limits the number of allowed MAC addresses on a port and can block unknown devices, while 802.1X ensures that only authenticated devices can access the network. Other features like DAI, IP Source Guard, and DHCP Snooping are useful for security but do not meet the specific requirements mentioned in the scenario.

  • A. Correct.

    Port Security is a feature that allows you to limit the number of MAC addresses that can be learned on a port. It also enables you to protect against MAC address table exhaustion attacks by statically configuring or limiting the number of allowed MAC addresses.

  • B. Correct.

    802.1X Authentication is a port-based network access control mechanism that ensures only authenticated devices can connect to the network. This helps prevent unauthorized devices from gaining access to the network.

  • C. Incorrect.

    Dynamic ARP Inspection (DAI) is used to prevent ARP spoofing attacks but does not directly address unauthorized device connections or MAC address table exhaustion.

  • D. Incorrect.

    IP Source Guard mitigates IP spoofing attacks by verifying the source IP address of packets but does not address unauthorized device connections or MAC address table exhaustion.

  • E. Incorrect.

    DHCP Snooping prevents rogue DHCP servers from assigning IP configurations to clients but is unrelated to protecting against unauthorized devices or MAC address table exhaustion.

Timed practice exam

Take a 300-440 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam