CompTIA Network+ (N10-009)Network SecurityMedium
Employees on a floor suddenly begin receiving IP addresses from an unauthorized 192.168.50.0/24 range instead of the corporate 10.10.10.0/24 range, and many cannot reach the internet. A technician suspects an unauthorized DHCP server was plugged into an access port. Which switch feature should be enabled to block DHCP offers arriving from untrusted ports?
- APort security
- BDHCP snooping
- CBPDU guard
- DDynamic ARP Inspection
Show answer & explanationAnswer & explanation
Correct answer: B. DHCP snooping
DHCP snooping builds a trusted/untrusted port database and blocks DHCP server responses (offers/acks) from ports not explicitly trusted, preventing rogue DHCP servers from handing out bogus leases. The other options address different threats (ARP poisoning, STP loops, MAC address abuse).
Why the other options are wrong
- A. Port security limits the number/identity of MAC addresses on a port, not DHCP traffic.
- C. BPDU guard protects against unauthorized switches causing STP topology changes.
- D. DAI validates ARP packets against a snooping-derived binding table, not DHCP offers directly.
DHCP Snooping
A switch security feature that classifies ports as trusted or untrusted and blocks DHCP server messages from untrusted ports to prevent rogue DHCP servers.
- Builds a binding table of IP-to-MAC-to-port mappings
- Untrusted ports cannot send DHCP offers/acks
- Foundation for Dynamic ARP Inspection
Memory trick: Trust the uplink, snoop the rest.