nerdexam
Cisco

350-701 · Question #439

An organization has DHCP servers set up to allocate IP addresses to clients on the LAN. What must be done to ensure the LAN switches prevent malicious DHCP traffic while also distributing IP…

The correct answer is D. Configure DHCP snooping and set a trusted interface for the DHCP server. DHCP snooping acts like a firewall between untrusted hosts and DHCP servers. You use DHCP snooping to differentiate between untrusted interfaces connected to the end user and trusted interfaces connected to the DHCP server or another switch.

Submitted by eva_at· Mar 30, 2026Network Security

Question

An organization has DHCP servers set up to allocate IP addresses to clients on the LAN. What must be done to ensure the LAN switches prevent malicious DHCP traffic while also distributing IP addresses to the correct endpoints?

Options

  • AConfigure Dynamic ARP Inspection and add entries in the DHCP snooping database
  • BConfigure DHCP snooping and set an untrusted interface for all clients
  • CConfigure Dynamic ARP Inspection and antispoofing ACLs in the DHCP snooping database
  • DConfigure DHCP snooping and set a trusted interface for the DHCP server

How the community answered

(22 responses)
  • A
    9% (2)
  • C
    5% (1)
  • D
    86% (19)

Explanation

DHCP snooping acts like a firewall between untrusted hosts and DHCP servers. You use DHCP snooping to differentiate between untrusted interfaces connected to the end user and trusted interfaces connected to the DHCP server or another switch.

Topics

#DHCP snooping#trusted interface#DHCP server#Layer 2 security

Community Discussion

No community discussion yet for this question.

Full 350-701 Practice