CompTIA Network+ (N10-009)Network SecurityMedium
Users on a subnet report intermittent connectivity issues, and a technician discovers that a workstation is broadcasting gratuitous ARP replies claiming to own the default gateway's IP address. Which mitigation, when configured on the switch, would have BEST prevented this?
- ADynamic ARP Inspection (DAI)
- BBPDU guard
- C802.1X authentication
- DPort security with MAC limiting
Show answer & explanationAnswer & explanation
Correct answer: A. Dynamic ARP Inspection (DAI)
Dynamic ARP Inspection (DAI) validates ARP packets against a trusted DHCP snooping binding table, dropping spoofed ARP replies that don't match the legitimate IP-to-MAC binding, directly preventing ARP spoofing.
Why the other options are wrong
- B. BPDU guard protects against rogue switches sending spanning-tree BPDUs, unrelated to ARP.
- C. 802.1X authenticates devices before granting network access but doesn't inspect ARP traffic.
- D. Port security limits the number of MAC addresses per port but doesn't validate ARP content.
Dynamic ARP Inspection (DAI)
A switch security feature that validates ARP packets against a trusted DHCP snooping database to prevent ARP spoofing/poisoning attacks.
- Relies on DHCP snooping binding table for validation
- Drops ARP packets with mismatched IP-to-MAC bindings
- Configured per VLAN on Layer 2/3 switches
Memory trick: DAI checks the ARP ID card before letting it in.