Cisco CCNA (200-301)Security FundamentalsMedium

Which statement best describes the primary function of Dynamic ARP Inspection (DAI) on a switch?

  1. AIt assigns static IP-to-MAC bindings for all hosts on the network
  2. BIt validates ARP packets against the DHCP snooping binding table to prevent ARP spoofing
  3. CIt encrypts ARP traffic between hosts on the same VLAN
  4. DIt limits the number of MAC addresses learned per switch port
Show answer & explanation

Correct answer: B. It validates ARP packets against the DHCP snooping binding table to prevent ARP spoofing

DAI intercepts ARP requests and replies and validates the IP-to-MAC bindings against the trusted DHCP snooping binding table (or static ARP ACLs), dropping packets that don't match to prevent ARP spoofing/man-in-the-middle attacks.

Why the other options are wrong

  • A. Static bindings can supplement DAI but are not its primary function.
  • C. DAI does not encrypt ARP traffic; it validates it.
  • D. That describes port security, not DAI.

Dynamic ARP Inspection (DAI)

A security feature that validates ARP packets using the DHCP snooping binding table to prevent ARP spoofing attacks.

  • Relies on DHCP snooping binding table
  • Drops ARP packets with mismatched IP-MAC bindings
  • Configured per VLAN, trusted ports skip inspection

Memory trick: DAI is the Detective checking ARP IDs against the Binding Book

More Security Fundamentals questions