nerdexam
Cisco

352-001 · Question #774

A customer requests a design that ensures that client devices are not dynamically configured with incorrect DNS information, which security technology must be configured on the switches when…

The correct answer is A. DHCP snooping. DHCP snooping is the switch-level security feature that prevents rogue DHCP servers from distributing incorrect IP configuration - including DNS server addresses - to client devices.

Designing Security

Question

A customer requests a design that ensures that client devices are not dynamically configured with incorrect DNS information, which security technology must be configured on the switches when finalizing the network design?

Options

  • ADHCP snooping
  • BDNS snooping
  • CRoot guard
  • DIGMP snooping

How the community answered

(44 responses)
  • A
    86% (38)
  • B
    7% (3)
  • C
    2% (1)
  • D
    5% (2)

Why each option

DHCP snooping is the switch-level security feature that prevents rogue DHCP servers from distributing incorrect IP configuration - including DNS server addresses - to client devices.

ADHCP snoopingCorrect

DHCP snooping acts as a firewall between untrusted client-facing ports and trusted uplinks, inspecting DHCP messages and dropping responses from unauthorized sources. Because DNS server assignments are delivered via DHCP offers, blocking rogue DHCP servers directly prevents clients from receiving incorrect DNS information. This is configured on switches at Layer 2 and enforced through a binding table of legitimate leases.

BDNS snooping

DNS snooping is not a recognized Cisco or IEEE switch security feature - it does not exist as a configurable technology on network switches.

CRoot guard

Root guard is a Spanning Tree Protocol feature that prevents an unauthorized switch from becoming the root bridge, and has no relationship to DHCP or DNS configuration.

DIGMP snooping

IGMP snooping is a multicast optimization that constrains Layer 2 multicast traffic to only the ports with interested receivers, completely unrelated to IP address or DNS assignment.

Concept tested: DHCP snooping to block rogue DHCP servers

Source: https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/ipaddr_dhcp/configuration/xe-16/dhcp-xe-16-book/config-dhcp-snooping.html

Topics

#DHCP snooping#DNS security#Layer 2 security#switch security

Community Discussion

No community discussion yet for this question.

Full 352-001 Practice