Cisco CCNA (200-301)Security FundamentalsMedium

An administrator is enabling Dynamic ARP Inspection on a switch. The uplink port connecting to the distribution switch must be allowed to relay ARP replies for many downstream hosts without inspection. Which command should be applied to that uplink interface?

  1. Ano ip arp inspection vlan 10
  2. Bip dhcp snooping trust
  3. Cip arp inspection trust
  4. Dip arp inspection limit rate 100
Show answer & explanation

Correct answer: C. ip arp inspection trust

To exempt an interface from DAI validation, the interface must be configured with 'ip arp inspection trust'. This is typically applied on uplinks toward distribution or core switches, similar in concept to DHCP snooping trust but as a separate command specific to ARP inspection.

Why the other options are wrong

  • A. This would disable ARP inspection entirely for the VLAN, which is far broader than intended.
  • B. This trusts the port for DHCP snooping only, not for ARP inspection.
  • D. This sets a rate limit for ARP packets, not a trust exemption.

DAI Trust Configuration

'ip arp inspection trust' configures an interface to bypass ARP packet validation, typically used on uplinks toward other switches.

  • Separate from 'ip dhcp snooping trust'
  • Applied per-interface
  • Untrusted ports are validated against DHCP snooping binding table

Memory trick: Trust the trunk, inspect the edge.

More Security Fundamentals questions