Cisco Certified Support Technician (CCST) CybersecurityNetwork SecurityMedium

A network administrator is troubleshooting an issue where a user's computer, connected to a wired network, is receiving an IP address from an unauthorized DHCP server configured by an attacker. This is causing the user to route traffic through the attacker's device. Which network security feature can mitigate this attack by allowing only trusted DHCP servers to provide IP addresses?

  1. ADHCP Snooping
  2. B802.1X Authentication
  3. CARP Inspection
  4. DMAC Address Filtering
Show answer & explanation

Correct answer: A. DHCP Snooping

DHCP Snooping is a Layer 2 security feature that prevents unauthorized DHCP servers from providing IP addresses to clients. It works by classifying switch ports as trusted (for legitimate DHCP servers) or untrusted (for client devices) and only allowing DHCP server messages from trusted ports.

Why the other options are wrong

  • B. 802.1X provides port-based authentication for network access but doesn't directly prevent rogue DHCP servers.
  • C. ARP Inspection validates ARP packets to prevent ARP spoofing, but not rogue DHCP servers.
  • D. MAC Address Filtering restricts which MAC addresses can connect to a port, but doesn't specifically address DHCP server issues.

DHCP Snooping

A Layer 2 security feature on a switch that filters DHCP messages to prevent unauthorized (rogue) DHCP servers from operating on the network.

  • Prevents rogue DHCP servers.
  • Classifies switch ports as trusted or untrusted.
  • Only allows DHCP server messages from trusted ports.
  • Mitigates man-in-the-middle attacks using rogue DHCP.

Memory trick: DHCP Snooping: The network's bouncer for DHCP servers, letting only the authorized ones in.

More Network Security questions