nerdexam
Juniper

JN0-348 · Question #30

Which two port security features are dependent on the DHCP snooping database? (Choose two.)

The correct answer is B. dynamic ARP inspection C. IP source guard. B: Dynamic ARP inspection (DAI) prevents Address Resolution Protocol (ARP) spoofing attacks. ARP requests and replies are compared against entries in the DHCP snooping database, and filtering decisions are made on the basis of the results of those comparisons. C: IP source…

Ethernet Switching Security

Question

Which two port security features are dependent on the DHCP snooping database? (Choose two.)

Options

  • AMAC limiting
  • Bdynamic ARP inspection
  • CIP source guard
  • Dstorm control

How the community answered

(27 responses)
  • A
    19% (5)
  • B
    74% (20)
  • D
    7% (2)

Explanation

B: Dynamic ARP inspection (DAI) prevents Address Resolution Protocol (ARP) spoofing attacks. ARP requests and replies are compared against entries in the DHCP snooping database, and filtering decisions are made on the basis of the results of those comparisons. C: IP source guard mitigates the effects of IP address spoofing attacks on the Ethernet LAN. With IP source guard enabled, the source IP address in the packet sent from an untrusted access interface is validated against t he source MAC address in the DHCP snooping database. The packet is forwarded if the source IP-MAC binding is valid; if the binding is not valid, the packet is discarded. You enable IP source guard on a VLAN. EX Series switches support IPv6 source

Topics

#DHCP snooping#dynamic ARP inspection#IP source guard#port security

Community Discussion

No community discussion yet for this question.

Full JN0-348 Practice