ExamGecko
Question list
Search
Search

Related questions











Question 100 - 312-50v12 discussion

Report
Export

DHCP snooping is a great solution to prevent rogue DHCP servers on your network. Which security feature on switchers leverages the DHCP snooping database to help prevent man-in-the-middle attacks?

A.
Spanning tree
Answers
A.
Spanning tree
B.
Dynamic ARP Inspection (DAI)
Answers
B.
Dynamic ARP Inspection (DAI)
C.
Port security
Answers
C.
Port security
D.
Layer 2 Attack Prevention Protocol (LAPP)
Answers
D.
Layer 2 Attack Prevention Protocol (LAPP)
Suggested answer: B

Explanation:

Dynamic ARP inspection (DAI) protects switching devices against Address Resolution Protocol (ARP) packet spoofing (also known as ARP poisoning or ARP cache poisoning).

DAI inspects ARPs on the LAN and uses the information in the DHCP snooping database on the switch to validate ARP packets and to protect against ARP spoofing. ARP requests and replies are compared against entries in the DHCP snooping database, and filtering decisions are made based on the results of those comparisons. When an attacker tries to use a forged ARP packet to spoof an address, the switch compares the address with entries in the database. If the media access control (MAC) address or IP address in the ARP packet does not match a valid entry in the DHCP snooping database, the packet is dropped.

asked 18/09/2024
Flora Hundal
32 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first