350-401 Question 249
Select 4You are tasked with securing a Layer 2 network that is vulnerable to attacks such as MAC address spoofing and DHCP starvation. Which combination of infrastructure security features should you configure on your Cisco switches to mitigate these threats effectively?
- A
Port Security
- B
DHCP Snooping
- C
Dynamic ARP Inspection (DAI)
- D
Access Control Lists (ACLs)
- E
IP Source Guard
Show answer and explanation
Correct answers: A, B, C, E
Explanation
To secure a Layer 2 network from MAC address spoofing and DHCP starvation, a combination of Port Security, DHCP Snooping, Dynamic ARP Inspection (DAI), and IP Source Guard is necessary. Port Security limits MAC addresses on a port, preventing spoofing. DHCP Snooping ensures only legitimate DHCP servers operate and builds a database. DAI uses the DHCP Snooping database to validate ARP packets and prevent spoofing attacks. IP Source Guard prevents IP spoofing by ensuring traffic matches DHCP Snooping bindings. ACLs, while useful for other purposes, do not directly address these Layer 2 threats.
- A. Correct.
Port Security allows you to restrict the number of MAC addresses per port and can prevent MAC address spoofing by allowing only specific MAC addresses on the port.
- B. Correct.
DHCP Snooping validates DHCP messages and builds a binding table to prevent DHCP starvation and rogue DHCP servers.
- C. Correct.
Dynamic ARP Inspection (DAI) works with DHCP Snooping to validate ARP packets and prevent ARP spoofing, which is often used in conjunction with MAC address spoofing.
- D. Incorrect.
Access Control Lists (ACLs) are used for filtering traffic based on Layer 3 and Layer 4 headers. While useful for traffic control, they do not directly mitigate Layer 2 threats like MAC address spoofing or DHCP starvation.
- E. Correct.
IP Source Guard works with DHCP Snooping to prevent IP spoofing by ensuring that traffic matches the IP-to-MAC bindings in the DHCP Snooping database.