200-301 · Question #18
Drag and Drop Question Drag and drop the threat-mitigation techniques from the left onto the types of threat or attack they mitigate on the right. Answer:
The correct answer is Configure VACL; Configure dynamic ARP inspection; Configure root guard; Configure BPDU guard. The correct arrangement maps each mitigation technique to its specific threat: VACLs (VLAN Access Control Lists) filter traffic within a VLAN to mitigate inter-VLAN or intra-VLAN attacks such as MAC/CAM table overflow or unauthorized access. Dynamic ARP Inspection (DAI) validates
Question
Exhibits
Answer Area
Drag items
Correct arrangement
- Configure VACL
- Configure dynamic ARP inspection
- Configure root guard
- Configure BPDU guard
Explanation
The correct arrangement maps each mitigation technique to its specific threat: VACLs (VLAN Access Control Lists) filter traffic within a VLAN to mitigate inter-VLAN or intra-VLAN attacks such as MAC/CAM table overflow or unauthorized access. Dynamic ARP Inspection (DAI) validates ARP packets against a DHCP snooping binding table to prevent ARP spoofing/poisoning attacks. Root Guard prevents unauthorized switches from becoming the STP root bridge, mitigating root bridge takeover attacks. BPDU Guard protects against rogue switches or loops by disabling a port that receives unexpected BPDU frames, typically on PortFast-enabled access ports.
Topics
Community Discussion
No community discussion yet for this question.

