Cisco CCNA (200-301)Security FundamentalsMedium
Which statement best describes the primary function of Dynamic ARP Inspection (DAI) on a switch?
- AIt assigns static IP-to-MAC bindings for all hosts on the network
- BIt validates ARP packets against the DHCP snooping binding table to prevent ARP spoofing
- CIt encrypts ARP traffic between hosts on the same VLAN
- DIt limits the number of MAC addresses learned per switch port
Show answer & explanationAnswer & explanation
Correct answer: B. It validates ARP packets against the DHCP snooping binding table to prevent ARP spoofing
DAI intercepts ARP requests and replies and validates the IP-to-MAC bindings against the trusted DHCP snooping binding table (or static ARP ACLs), dropping packets that don't match to prevent ARP spoofing/man-in-the-middle attacks.
Why the other options are wrong
- A. Static bindings can supplement DAI but are not its primary function.
- C. DAI does not encrypt ARP traffic; it validates it.
- D. That describes port security, not DAI.
Dynamic ARP Inspection (DAI)
A security feature that validates ARP packets using the DHCP snooping binding table to prevent ARP spoofing attacks.
- Relies on DHCP snooping binding table
- Drops ARP packets with mismatched IP-MAC bindings
- Configured per VLAN, trusted ports skip inspection
Memory trick: DAI is the Detective checking ARP IDs against the Binding Book