nerdexam
Cisco

350-701 · Question #430

Refer to the exhibit. The DHCP snooping database resides on router R1, and dynamic ARP inspection is configured only on switch SW2. Which ports must be configured as untrusted so that dynamic ARP…

The correct answer is D. P2, P3, and P6 only. To handle cases in which some switches in a VLAN run DAI and other switches do not, the interfaces connecting such switches should be configured as untrusted. To validate the bindings of packets from non-DAI switches, however, the switch running DAI should be configured with…

Submitted by obi.ng· Mar 30, 2026Network Security

Question

Refer to the exhibit. The DHCP snooping database resides on router R1, and dynamic ARP inspection is configured only on switch SW2. Which ports must be configured as untrusted so that dynamic ARP inspection operates normally?

Exhibit

350-701 question #430 exhibit

Options

  • AP2 and P3 only
  • BP5, P6, and P7 only
  • CP1, P2, P3, and P4 only
  • DP2, P3, and P6 only

How the community answered

(27 responses)
  • A
    7% (2)
  • B
    30% (8)
  • C
    19% (5)
  • D
    44% (12)

Explanation

To handle cases in which some switches in a VLAN run DAI and other switches do not, the interfaces connecting such switches should be configured as untrusted. To validate the bindings of packets from non-DAI switches, however, the switch running DAI should be configured with ARP ACLs. When it is not feasible to determine such bindings, switches running DAI should be isolated from non-DAI switches at Layer 3.

Topics

#dynamic ARP inspection#DHCP snooping#trusted untrusted ports#Layer 2 security

Community Discussion

No community discussion yet for this question.

Full 350-701 Practice