nerdexam
CiscoCisco

350-401 · Question #763

350-401 Question #763: Real Exam Question with Answer & Explanation

The correct answer is A: ip verify source tracking. To enable IP Source Guard with both IP and MAC address filtering, commands like ip verify source tracking leverage DHCP snooping bindings, and ip verify source port-security integrates with port security.

Submitted by thandi_sa· Mar 6, 2026

Question

Which two commands should you enter to enable IP Source Guard with IP and MAC address filtering?(Choose two)

Options

  • Aip verify source tracking
  • Bswitchport port-security
  • Cip verify unicast source
  • Dip verify source
  • Eip verify source port-security

Explanation

To enable IP Source Guard with both IP and MAC address filtering, commands like ip verify source tracking leverage DHCP snooping bindings, and ip verify source port-security integrates with port security.

Common mistakes.

  • B. The switchport port-security command enables port security but does not directly enable IP Source Guard or its filtering mechanisms.
  • C. The ip verify unicast source command is not the standard or primary command for enabling IP Source Guard with comprehensive IP and MAC address filtering.
  • D. The ip verify source command alone enables IP Source Guard, but for explicit IP and MAC address filtering, more specific keywords like tracking or port-security are typically used.

Concept tested. IP Source Guard configuration with IP and MAC filtering

Reference. https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_data_snooping/configuration/xe-3s/sec-data-snooping-xe-3s-book/sec-ip-src-guard.html

Topics

#IP Source Guard#Cisco switch security#Layer 2 security#IOS configuration

Community Discussion

No community discussion yet for this question.

Full 350-401 PracticeBrowse All 350-401 Questions