200-301 · Question #658
Drag and Drop Question Drag and drop the Cisco IOS attack mitigation features from the left onto the types of network attack they mitigate on the right. Answer:
The correct answer is rogue server that spoofs IP configuration; cache poisoning; rogue clients on the network; flood attacks. DHCP Snooping mitigates rogue DHCP servers that spoof IP configuration by filtering untrusted DHCP responses. Dynamic ARP Inspection (DAI) prevents ARP cache poisoning by validating ARP packets against the DHCP snooping binding table. IP Source Guard mitigates rogue clients on th
Question
Drag and Drop Question Drag and drop the Cisco IOS attack mitigation features from the left onto the types of network attack they mitigate on the right. Answer:
Exhibits
Answer Area
Drag items
Correct arrangement
- rogue server that spoofs IP configuration
- cache poisoning
- rogue clients on the network
- flood attacks
Explanation
DHCP Snooping mitigates rogue DHCP servers that spoof IP configuration by filtering untrusted DHCP responses. Dynamic ARP Inspection (DAI) prevents ARP cache poisoning by validating ARP packets against the DHCP snooping binding table. IP Source Guard mitigates rogue clients on the network by filtering traffic based on the IP-to-MAC-to-port binding, and Storm Control mitigates flood attacks (broadcast, multicast, or unicast storms) by limiting the rate of traffic on a port.
Topics
Community Discussion
No community discussion yet for this question.

