nerdexam
HP

HPE6-A78 · Question #78

This company has AOS-CX switches. The exhibit shows one access layer switch, Switch-2, as an example, but the campus actually has more switches. Switch-1 is a core switch that acts as the default…

The correct answer is B. On Switch-2, enable DHCP snooping globally and on VLANs 15 and 25. Later, enable ARP. The scenario involves AOS-CX switches in a two-tier topology with Switch-1 as the core switch (default router) on VLAN 100 and Switch-2 as an access layer switch with VLANs 15 and 25, where end-user devices connect. The goal is to protect against exploits from untrusted…

Implementing and Configuring Aruba Network Security

Question

This company has AOS-CX switches. The exhibit shows one access layer switch, Switch-2, as an example, but the campus actually has more switches. Switch-1 is a core switch that acts as the default router for end-user devices. What is a correct way to configure the switches to protect against exploits from untrusted end- user devices?

Exhibit

HPE6-A78 question #78 exhibit

Options

  • AOn Switch-1, enable ARP inspection on VLAN 100 and DHCP snooping on VLANs 15 and 25.
  • BOn Switch-2, enable DHCP snooping globally and on VLANs 15 and 25. Later, enable ARP
  • COn Switch-2, enable BPDU filtering on all edge ports in order to prevent eavesdropping attacks by
  • DOn Switch-1, enable DHCP snooping on VLAN 100 and ARP inspection on VLANs 15 and 25.

How the community answered

(39 responses)
  • A
    23% (9)
  • B
    59% (23)
  • C
    5% (2)
  • D
    13% (5)

Explanation

The scenario involves AOS-CX switches in a two-tier topology with Switch-1 as the core switch (default router) on VLAN 100 and Switch-2 as an access layer switch with VLANs 15 and 25, where end-user devices connect. The goal is to protect against exploits from untrusted end-user devices, such as DHCP spoofing or ARP poisoning attacks, which are common threats in access layer networks. DHCP Snooping: This feature protects against rogue DHCP servers by filtering DHCP messages. It should be enabled on the access layer switch (Switch-2) where end-user devices connect, specifically on the VLANs where these devices reside (VLANs 15 and 25). DHCP snooping builds a binding table of legitimate IP-to-MAC mappings, which can be used by other features like ARP inspection. ARP Inspection: This feature prevents ARP poisoning attacks by validating ARP packets against the DHCP snooping binding table. It should also be enabled on the access layer switch (Switch-2) on VLANs 15 and 25, where untrusted devices are connected. Option B, "On Switch-2, enable DHCP snooping globally and on VLANs 15 and 25. Later, enable ARP inspection on the same VLANs," is correct. DHCP snooping must be enabled first to build the binding table, and then ARP inspection can use this table to validate ARP packets. This configuration should be applied on Switch-2, the access layer switch, because that's where untrusted end-user devices connect.

Topics

#DHCP snooping#ARP inspection#AOS-CX#layer 2 security

Community Discussion

No community discussion yet for this question.

Full HPE6-A78 Practice