Implementing and Operating Cisco Enterprise Network Core Technologies (ENCOR) v1.2InfrastructureEasy

A network technician is configuring an access layer switch for a new office. Users connecting to this switch will receive their IP configuration from a DHCP server on a different VLAN. To prevent unauthorized or rogue DHCP servers from operating on the network, which feature should be enabled on the switch ports connected to end-user devices?

  1. AIP Source Guard
  2. BDynamic ARP Inspection
  3. CDHCP Snooping
  4. DPort Security
Show answer & explanation

Correct answer: C. DHCP Snooping

DHCP Snooping is designed to prevent rogue DHCP servers from providing IP addresses to clients and to build a binding table used by other security features like IP Source Guard and Dynamic ARP Inspection.

Why the other options are wrong

  • A. IP Source Guard uses the DHCP snooping binding table to prevent IP address spoofing, not primarily rogue DHCP servers.
  • B. Dynamic ARP Inspection (DAI) prevents ARP spoofing and poisoning by validating ARP packets against the DHCP snooping binding table.
  • D. Port Security restricts the number of MAC addresses on a port and can limit specific MACs, but doesn't directly prevent rogue DHCP servers.

DHCP Snooping

DHCP Snooping is a Layer 2 security feature that filters untrusted DHCP messages and builds a binding database to prevent rogue DHCP servers and enhance network security.

  • Prevents rogue DHCP servers.
  • Builds a DHCP snooping binding table.
  • Classifies ports as trusted or untrusted.
  • Used by IP Source Guard and Dynamic ARP Inspection.

Memory trick: Snoop out the rogue, Guard the source, Inspect the ARP, Secure the port.

More Infrastructure questions