350-701 · Question #866
A networking team must harden an organization's core switch against man-in-the-middle attacks. The team must use Dynamic ARP Inspection on the switch to meet the requirement. The team enables DHCP…
The correct answer is B. Apply ARP access control lists for Dynamic ARP Inspection filtering. To complete the configuration of Dynamic ARP Inspection (DAI), you must apply ARP access control lists (ACLs) to specify which ARP packets are permitted or denied. DAI relies on information from DHCP snooping or ARP ACLs to validate ARP requests and responses. Without ARP ACLs…
Question
A networking team must harden an organization’s core switch against man-in-the-middle attacks. The team must use Dynamic ARP Inspection on the switch to meet the requirement. The team enables DHCP snooping and Dynamic ARP Inspection and configures the trust state of the service. Which action must be taken next to complete the configuration of the Dynamic ARP Inspection feature?
Options
- AEnable Dynamic ARP Inspection error-disabled recovery.
- BApply ARP access control lists for Dynamic ARP Inspection filtering.
- CEnable Dynamic ARP Inspection logging for dropped packets.
- DConfigure the ARP packet rate limiting feature.
How the community answered
(41 responses)- A10% (4)
- B85% (35)
- C2% (1)
- D2% (1)
Explanation
To complete the configuration of Dynamic ARP Inspection (DAI), you must apply ARP access control lists (ACLs) to specify which ARP packets are permitted or denied. DAI relies on information from DHCP snooping or ARP ACLs to validate ARP requests and responses. Without ARP ACLs or DHCP snooping binding, the DAI feature cannot determine which ARP packets are legitimate, leaving the switch unprotected.
Topics
Community Discussion
No community discussion yet for this question.