HPE7-A08 · Question #74
Refer to the exhibit: SW-A is the layer-3 gateway for: Server-A in VLAN 100, subnet 10.100.100.0/24 Client-A in VLAN 20, subnet 10.100.20.0/24 Client-B VLAN 30, subnet 10.100.30.0/24 What must be…
The correct answer is D. Enable dhcpv4-snooping globally and on VLAN 20. To prevent rogue DHCP servers on VLAN 20, you must: Enable DHCP snooping globally Enable DHCP snooping on the specific VLAN (VLAN 20) This ensures that only trusted ports (uplinks toward the real DHCP server) can send DHCP offers. SW-A is the L3 gateway, and Server-A…
Question
Refer to the exhibit:
SW-A is the layer-3 gateway for:
Server-A in VLAN 100, subnet 10.100.100.0/24 Client-A in VLAN 20, subnet 10.100.20.0/24 Client-B VLAN 30, subnet 10.100.30.0/24 What must be done to prevent rogue DHCP servers in VLAN 20 on SW-A?
Exhibit
Options
- AEnable dhcpv4-snooping globally and on interface VLAN 20
- BEnable dhcpv4-snooping trust 10.100.100.10 on VLAN 20
- CEnable dhcpv4-snooping authorized-server 10.100.100.10 on VLAN 20
- DEnable dhcpv4-snooping globally and on VLAN 20
How the community answered
(22 responses)- A9% (2)
- B9% (2)
- C5% (1)
- D77% (17)
Explanation
To prevent rogue DHCP servers on VLAN 20, you must: Enable DHCP snooping globally Enable DHCP snooping on the specific VLAN (VLAN 20) This ensures that only trusted ports (uplinks toward the real DHCP server) can send DHCP offers. SW-A is the L3 gateway, and Server-A (10.100.100.10) is not in VLAN 20 -- so options that try to authorize it under VLAN 20 are invalid. Correct configuration approach: dhcpv4-snooping vlan 20
Topics
Community Discussion
No community discussion yet for this question.
