Implementing and Operating Cisco Enterprise Network Core Technologies (ENCOR) v1.2InfrastructureEasy
A network technician is configuring an access layer switch for a new office. Users connecting to this switch will receive their IP configuration from a DHCP server on a different VLAN. To prevent unauthorized or rogue DHCP servers from operating on the network, which feature should be enabled on the switch ports connected to end-user devices?
- AIP Source Guard
- BDynamic ARP Inspection
- CDHCP Snooping
- DPort Security
Show answer & explanationAnswer & explanation
Correct answer: C. DHCP Snooping
DHCP Snooping is designed to prevent rogue DHCP servers from providing IP addresses to clients and to build a binding table used by other security features like IP Source Guard and Dynamic ARP Inspection.
Why the other options are wrong
- A. IP Source Guard uses the DHCP snooping binding table to prevent IP address spoofing, not primarily rogue DHCP servers.
- B. Dynamic ARP Inspection (DAI) prevents ARP spoofing and poisoning by validating ARP packets against the DHCP snooping binding table.
- D. Port Security restricts the number of MAC addresses on a port and can limit specific MACs, but doesn't directly prevent rogue DHCP servers.
DHCP Snooping
DHCP Snooping is a Layer 2 security feature that filters untrusted DHCP messages and builds a binding database to prevent rogue DHCP servers and enhance network security.
- Prevents rogue DHCP servers.
- Builds a DHCP snooping binding table.
- Classifies ports as trusted or untrusted.
- Used by IP Source Guard and Dynamic ARP Inspection.
Memory trick: Snoop out the rogue, Guard the source, Inspect the ARP, Secure the port.