nerdexam
Cisco

200-301 · Question #658

Drag and Drop Question Drag and drop the Cisco IOS attack mitigation features from the left onto the types of network attack they mitigate on the right. Answer:

The correct answer is rogue server that spoofs IP configuration; cache poisoning; rogue clients on the network; flood attacks. DHCP Snooping mitigates rogue DHCP servers that spoof IP configuration by filtering untrusted DHCP responses. Dynamic ARP Inspection (DAI) prevents ARP cache poisoning by validating ARP packets against the DHCP snooping binding table. IP Source Guard mitigates rogue clients on th

Submitted by naveen.iyer· Mar 5, 2026Infrastructure Security – Cisco IOS Layer 2 attack mitigation features (CCNA/CCNP Security or Enterprise domains)

Question

Drag and Drop Question Drag and drop the Cisco IOS attack mitigation features from the left onto the types of network attack they mitigate on the right. Answer:

Exhibits

200-301 question #658 exhibit 1
200-301 question #658 exhibit 2

Answer Area

Drag items

DHCP snoopingDynamic ARP InspectionIP Source Guardstorm control

Correct arrangement

  • rogue server that spoofs IP configuration
  • cache poisoning
  • rogue clients on the network
  • flood attacks

Explanation

DHCP Snooping mitigates rogue DHCP servers that spoof IP configuration by filtering untrusted DHCP responses. Dynamic ARP Inspection (DAI) prevents ARP cache poisoning by validating ARP packets against the DHCP snooping binding table. IP Source Guard mitigates rogue clients on the network by filtering traffic based on the IP-to-MAC-to-port binding, and Storm Control mitigates flood attacks (broadcast, multicast, or unicast storms) by limiting the rate of traffic on a port.

Topics

#Layer 2 Security#DHCP Snooping#Dynamic ARP Inspection#Network Attack Mitigation

Community Discussion

No community discussion yet for this question.

Full 200-301 Practice