nerdexam
HP

HPE7-A08 · Question #74

Refer to the exhibit: SW-A is the layer-3 gateway for: Server-A in VLAN 100, subnet 10.100.100.0/24 Client-A in VLAN 20, subnet 10.100.20.0/24 Client-B VLAN 30, subnet 10.100.30.0/24 What must be…

The correct answer is D. Enable dhcpv4-snooping globally and on VLAN 20. To prevent rogue DHCP servers on VLAN 20, you must: Enable DHCP snooping globally Enable DHCP snooping on the specific VLAN (VLAN 20) This ensures that only trusted ports (uplinks toward the real DHCP server) can send DHCP offers. SW-A is the L3 gateway, and Server-A…

Perform HPE Aruba Networking CX Switch Configurations

Question

Refer to the exhibit:

SW-A is the layer-3 gateway for:

Server-A in VLAN 100, subnet 10.100.100.0/24 Client-A in VLAN 20, subnet 10.100.20.0/24 Client-B VLAN 30, subnet 10.100.30.0/24 What must be done to prevent rogue DHCP servers in VLAN 20 on SW-A?

Exhibit

HPE7-A08 question #74 exhibit

Options

  • AEnable dhcpv4-snooping globally and on interface VLAN 20
  • BEnable dhcpv4-snooping trust 10.100.100.10 on VLAN 20
  • CEnable dhcpv4-snooping authorized-server 10.100.100.10 on VLAN 20
  • DEnable dhcpv4-snooping globally and on VLAN 20

How the community answered

(22 responses)
  • A
    9% (2)
  • B
    9% (2)
  • C
    5% (1)
  • D
    77% (17)

Explanation

To prevent rogue DHCP servers on VLAN 20, you must: Enable DHCP snooping globally Enable DHCP snooping on the specific VLAN (VLAN 20) This ensures that only trusted ports (uplinks toward the real DHCP server) can send DHCP offers. SW-A is the L3 gateway, and Server-A (10.100.100.10) is not in VLAN 20 -- so options that try to authorize it under VLAN 20 are invalid. Correct configuration approach: dhcpv4-snooping vlan 20

Topics

#DHCP snooping#rogue DHCP#VLAN security#Layer 2 security

Community Discussion

No community discussion yet for this question.

Full HPE7-A08 Practice