HPE6-A78 · Question #169
Refer to the exhibit. This company has ArubaOS-Switches. The exhibit shows one access layer switch, Switch-2 as an example, but the campus actually has more switches. The company wants to slop any…
The correct answer is C. On Swltch-2, enable DHCP snooping globally and on VLAN 201 before enabling ARP protection. To prevent users from exploiting Address Resolution Protocol (ARP) on a network with ArubaOS- Switches, the correct approach would be to enable DHCP snooping globally and on VLAN 201 before enabling ARP protection, as stated in option C. DHCP snooping acts as a foundation by…
Question
Refer to the exhibit. This company has ArubaOS-Switches. The exhibit shows one access layer switch, Switch-2 as an example, but the campus actually has more switches. The company wants to slop any internal users from exploiting ARP. What Is the proper way to configure the switches to meet these requirements?
Exhibit
Options
- AOn Switch-1, enable ARP protection globally, and enable ARP protection on ail VLANs.
- BOn Switch-2, make ports connected to employee devices trusted ports for ARP protection
- COn Swltch-2, enable DHCP snooping globally and on VLAN 201 before enabling ARP protection
- DOn Swltch-2, configure static PP-to-MAC bindings for all end-user devices on the network
How the community answered
(27 responses)- B7% (2)
- C81% (22)
- D11% (3)
Explanation
To prevent users from exploiting Address Resolution Protocol (ARP) on a network with ArubaOS- Switches, the correct approach would be to enable DHCP snooping globally and on VLAN 201 before enabling ARP protection, as stated in option C. DHCP snooping acts as a foundation by tracking and securing the association of IP addresses to MAC addresses. This allows ARP protection to function effectively by ensuring that only valid ARP requests and responses are processed, thus preventing ARP spoofing attacks. Trusting ports that connect to employee devices directly could lead to bypassing ARP protection if those devices are compromised.
Topics
Community Discussion
No community discussion yet for this question.
