nerdexam
Cisco

352-001 · Question #145

Your design client has requested that you ensure that the client devices are not dynamically configured with incorrect DNS information. When finalizing the network design, which security option must…

The correct answer is B. DHCP snooping. DHCP snooping prevents rogue DHCP servers from distributing incorrect IP and DNS configuration to client devices on the network.

Designing Security

Question

Your design client has requested that you ensure that the client devices are not dynamically configured with incorrect DNS information. When finalizing the network design, which security option must be configured on the switches?

Options

  • AIGMP snooping
  • BDHCP snooping
  • Croot guard
  • DDNS snooping

How the community answered

(54 responses)
  • A
    2% (1)
  • B
    91% (49)
  • C
    2% (1)
  • D
    6% (3)

Why each option

DHCP snooping prevents rogue DHCP servers from distributing incorrect IP and DNS configuration to client devices on the network.

AIGMP snooping

IGMP snooping manages multicast group membership traffic and has no function related to DHCP or DNS address assignment.

BDHCP snoopingCorrect

DHCP snooping is a Layer 2 security feature configured on switches that designates ports as trusted or untrusted. Untrusted ports drop DHCP server responses, preventing rogue DHCP servers from distributing incorrect DNS server addresses or gateway information to clients. This directly addresses the requirement to protect clients from receiving incorrect DNS configuration.

Croot guard

Root guard is a Spanning Tree Protocol feature that prevents unauthorized switches from becoming the root bridge, and does not interact with DHCP or DNS.

DDNS snooping

DNS snooping is not a defined or standard switch security feature; it does not exist as a configurable option on network switches.

Concept tested: DHCP snooping to prevent rogue DHCP servers

Source: https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst6500/ios/12-2SX/configuration/guide/book/snoodhcp.html

Topics

#DHCP snooping#rogue DHCP prevention#DNS security#Layer 2 security

Community Discussion

No community discussion yet for this question.

Full 352-001 Practice