352-001 · Question #145
Your design client has requested that you ensure that the client devices are not dynamically configured with incorrect DNS information. When finalizing the network design, which security option must…
The correct answer is B. DHCP snooping. DHCP snooping prevents rogue DHCP servers from distributing incorrect IP and DNS configuration to client devices on the network.
Question
Your design client has requested that you ensure that the client devices are not dynamically configured with incorrect DNS information. When finalizing the network design, which security option must be configured on the switches?
Options
- AIGMP snooping
- BDHCP snooping
- Croot guard
- DDNS snooping
How the community answered
(54 responses)- A2% (1)
- B91% (49)
- C2% (1)
- D6% (3)
Why each option
DHCP snooping prevents rogue DHCP servers from distributing incorrect IP and DNS configuration to client devices on the network.
IGMP snooping manages multicast group membership traffic and has no function related to DHCP or DNS address assignment.
DHCP snooping is a Layer 2 security feature configured on switches that designates ports as trusted or untrusted. Untrusted ports drop DHCP server responses, preventing rogue DHCP servers from distributing incorrect DNS server addresses or gateway information to clients. This directly addresses the requirement to protect clients from receiving incorrect DNS configuration.
Root guard is a Spanning Tree Protocol feature that prevents unauthorized switches from becoming the root bridge, and does not interact with DHCP or DNS.
DNS snooping is not a defined or standard switch security feature; it does not exist as a configurable option on network switches.
Concept tested: DHCP snooping to prevent rogue DHCP servers
Source: https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst6500/ios/12-2SX/configuration/guide/book/snoodhcp.html
Topics
Community Discussion
No community discussion yet for this question.