CompTIA Network+ (N10-009)Network SecurityMedium

Users on a subnet report intermittent connectivity issues, and a technician discovers that a workstation is broadcasting gratuitous ARP replies claiming to own the default gateway's IP address. Which mitigation, when configured on the switch, would have BEST prevented this?

  1. ADynamic ARP Inspection (DAI)
  2. BBPDU guard
  3. C802.1X authentication
  4. DPort security with MAC limiting
Show answer & explanation

Correct answer: A. Dynamic ARP Inspection (DAI)

Dynamic ARP Inspection (DAI) validates ARP packets against a trusted DHCP snooping binding table, dropping spoofed ARP replies that don't match the legitimate IP-to-MAC binding, directly preventing ARP spoofing.

Why the other options are wrong

  • B. BPDU guard protects against rogue switches sending spanning-tree BPDUs, unrelated to ARP.
  • C. 802.1X authenticates devices before granting network access but doesn't inspect ARP traffic.
  • D. Port security limits the number of MAC addresses per port but doesn't validate ARP content.

Dynamic ARP Inspection (DAI)

A switch security feature that validates ARP packets against a trusted DHCP snooping database to prevent ARP spoofing/poisoning attacks.

  • Relies on DHCP snooping binding table for validation
  • Drops ARP packets with mismatched IP-to-MAC bindings
  • Configured per VLAN on Layer 2/3 switches

Memory trick: DAI checks the ARP ID card before letting it in.

More Network Security questions