Cisco Certified Support Technician (CCST) CybersecurityNetwork SecurityHard

A network technician is troubleshooting a network connectivity issue where a new host cannot obtain an IP address from the DHCP server. Upon inspection, the technician discovers that the switch port to which the host is connected has been configured to only allow DHCP messages from trusted ports, and this specific port is not trusted. Which security feature is likely preventing the host from getting an IP address?

  1. A802.1X Authentication
  2. BDHCP Snooping
  3. CPort Mirroring
  4. DSTP Root Guard
Show answer & explanation

Correct answer: B. DHCP Snooping

DHCP Snooping is a security feature that filters untrusted DHCP messages and builds a trusted binding table. If a switch port is configured as untrusted, it will drop DHCP server responses arriving on that port, preventing the host from obtaining an IP address, which perfectly matches the scenario.

Why the other options are wrong

  • A. 802.1X authenticates devices or users before granting network access, but the scenario specifically points to DHCP message filtering, not general network access.
  • C. Port Mirroring (SPAN) copies traffic for analysis, it doesn't block DHCP.
  • D. STP Root Guard prevents unauthorized devices from becoming the Spanning Tree Protocol root bridge, unrelated to DHCP address assignment.

DHCP Snooping

DHCP Snooping is a switch security feature that acts as a firewall between untrusted hosts and trusted DHCP servers, preventing rogue DHCP servers and enforcing DHCP lease integrity.

  • Filters DHCP messages based on trusted/untrusted ports
  • Prevents rogue DHCP servers
  • Builds and maintains a DHCP binding table

Memory trick: Snooping 'snoops' on DHCP to keep it honest.

More Network Security questions