Cisco CCNA 200-301 Layer 2 Security Practice Test

Topic 37 focuses on Layer 2 Security for the Cisco Certified Network Associate (CCNA) certification and the 200-301 exam, using Cisco networking and Cisco IOS concepts where relevant. For broader exam preparation, review the Cisco CCNA 200-301 Exam Dumps page. Each question includes a concise explanation of the correct answer and the technical reason the other choices are incorrect.

Question 1

Which Layer 2 security feature filters DHCP messages and builds a binding table from legitimate DHCP assignments?

  1. Untrusted DHCP snooping port
  2. Sticky MAC
  3. DHCP snooping
  4. Dynamic ARP Inspection

Correct Answer: C

 

Correct Answer

Answer C is correct because the selected answer describes a Layer 2 security feature that filters DHCP messages and builds a binding table from legitimate DHCP assignments.

Incorrect Answers

Answer A is incorrect because the “Untrusted DHCP snooping port” option describes a different concept: a switch port on which DHCP server messages are normally rejected to help block rogue DHCP servers.

Answer B is incorrect because the “Sticky MAC” option describes a different concept: a port-security feature that dynamically learns secure MAC addresses and adds them to the running configuration.

Answer D is incorrect because the “Dynamic ARP Inspection” option describes a different concept: a switch security feature that validates ARP messages against trusted information such as the DHCP snooping database.

 

Question 2

What is a switch port allowed to send DHCP server messages such as Offer and ACK messages?

  1. Dynamic ARP Inspection
  2. DHCP snooping rate limiting
  3. Untrusted DHCP snooping port
  4. Trusted DHCP snooping port

Correct Answer: D

 

Correct Answer

Answer D is correct because the selected answer describes a switch port allowed to send DHCP server messages such as Offer and ACK messages.

Incorrect Answers

Answer A is incorrect because the “Dynamic ARP Inspection” option describes a different concept: a switch security feature that validates ARP messages against trusted information such as the DHCP snooping database.

Answer B is incorrect because the “DHCP snooping rate limiting” option describes a different concept: DHCP snooping can rate-limit DHCP messages on untrusted ports to reduce abuse and denial-of-service behavior.

Answer C is incorrect because the “Untrusted DHCP snooping port” option describes a different concept: a switch port on which DHCP server messages are normally rejected to help block rogue DHCP servers.

 

Question 3

What is a switch port on which DHCP server messages are normally rejected to help block rogue DHCP servers?

  1. Untrusted DHCP snooping port
  2. DHCP snooping binding table
  3. Trusted DHCP snooping port
  4. Port security

Correct Answer: A

 

Correct Answer

Answer A is correct because the selected answer describes a switch port on which DHCP server messages are normally rejected to help block rogue DHCP servers.

Incorrect Answers

Answer B is incorrect because the “DHCP snooping binding table” option describes a different concept: a table that records legitimate client MAC, IP, VLAN, port, and lease information learned from DHCP.

Answer C is incorrect because the “Trusted DHCP snooping port” option describes a different concept: a switch port allowed to send DHCP server messages such as Offer and ACK messages.

Answer D is incorrect because the “Port security” option describes a different concept: a switch feature that restricts which source MAC addresses are allowed on an access port.

 

Question 4

Which table records legitimate client MAC, IP, VLAN, port, and lease information learned from DHCP?

  1. Dynamic ARP Inspection
  2. DHCP snooping
  3. DHCP snooping binding table
  4. Secure MAC address

Correct Answer: C

 

Correct Answer

Answer C is correct because the selected answer describes a table that records legitimate client MAC, IP, VLAN, port, and lease information learned from DHCP.

Incorrect Answers

Answer A is incorrect because the “Dynamic ARP Inspection” option describes a different concept: a switch security feature that validates ARP messages against trusted information such as the DHCP snooping database.

Answer B is incorrect because the “DHCP snooping” option describes a different concept: a Layer 2 security feature that filters DHCP messages and builds a binding table from legitimate DHCP assignments.

Answer D is incorrect because the “Secure MAC address” option describes a different concept: a secure MAC address is a source MAC address explicitly or dynamically permitted by port security on an interface.

 

Question 5

Which switch security feature validates ARP messages against trusted information such as the DHCP snooping database?

  1. DAI validation
  2. Dynamic ARP Inspection
  3. DAI trusted port
  4. Port security

Correct Answer: B

 

Correct Answer

Answer B is correct because the selected answer describes a switch security feature that validates ARP messages against trusted information such as the DHCP snooping database.

Incorrect Answers

Answer A is incorrect because the “DAI validation” option describes a different concept: Dynamic ARP Inspection checks ARP information against trusted bindings or configured ARP information to detect spoofed ARP messages.

Answer C is incorrect because the “DAI trusted port” option describes a different concept: a trusted Dynamic ARP Inspection port bypasses normal ARP validation and is typically reserved for carefully controlled infrastructure links.

Answer D is incorrect because the “Port security” option describes a different concept: a switch feature that restricts which source MAC addresses are allowed on an access port.

 

Question 6

Which switch feature restricts which source MAC addresses are allowed on an access port?

  1. Port security
  2. Sticky MAC
  3. DHCP snooping
  4. Port-security aging

Correct Answer: A

 

Correct Answer

Answer A is correct because the selected answer describes a switch feature that restricts which source MAC addresses are allowed on an access port.

Incorrect Answers

Answer B is incorrect because the “Sticky MAC” option describes a different concept: a port-security feature that dynamically learns secure MAC addresses and adds them to the running configuration.

Answer C is incorrect because the “DHCP snooping” option describes a different concept: a Layer 2 security feature that filters DHCP messages and builds a binding table from legitimate DHCP assignments.

Answer D is incorrect because the “Port-security aging” option describes a different concept: Port-security aging can remove dynamically learned secure MAC addresses after configured conditions or time intervals.

 

Question 7

Which port-security feature dynamically learns secure MAC addresses and adds them to the running configuration?

  1. Port-security maximum
  2. Port security
  3. Shutdown violation mode
  4. Sticky MAC

Correct Answer: D

 

Correct Answer

Answer D is correct because the selected answer describes a port-security feature that dynamically learns secure MAC addresses and adds them to the running configuration.

Incorrect Answers

Answer A is incorrect because the “Port-security maximum” option describes a different concept: the port-security maximum setting controls how many secure MAC addresses are permitted on an interface.

Answer B is incorrect because the “Port security” option describes a different concept: a switch feature that restricts which source MAC addresses are allowed on an access port.

Answer C is incorrect because the “Shutdown violation mode” option describes a different concept: the default port-security violation mode that places the interface into an error-disabled state after a violation.

 

Question 8

Which port-security mode drops frames from unauthorized MAC addresses without shutting the port down?

  1. Port security
  2. Port-security maximum
  3. Protect violation mode
  4. Err-disabled recovery after port-security shutdown

Correct Answer: C

 

Correct Answer

Answer C is correct because the selected answer describes a port-security mode that drops frames from unauthorized MAC addresses without shutting the port down.

Incorrect Answers

Answer A is incorrect because the “Port security” option describes a different concept: a switch feature that restricts which source MAC addresses are allowed on an access port.

Answer B is incorrect because the “Port-security maximum” option describes a different concept: the port-security maximum setting controls how many secure MAC addresses are permitted on an interface.

Answer D is incorrect because the “Err-disabled recovery after port-security shutdown” option describes a different concept: After a shutdown-mode port-security violation, the interface is typically error-disabled until the condition is corrected and the interface is recovered manually or by configured recovery.

 

Question 9

Which port-security mode drops unauthorized frames and increments/logs violations while keeping the port up?

  1. Port-security aging
  2. Restrict violation mode
  3. Err-disabled recovery after port-security shutdown
  4. Port security

Correct Answer: B

 

Correct Answer

Answer B is correct because the selected answer describes a port-security mode that drops unauthorized frames and increments/logs violations while keeping the port up.

Incorrect Answers

Answer A is incorrect because the “Port-security aging” option describes a different concept: Port-security aging can remove dynamically learned secure MAC addresses after configured conditions or time intervals.

Answer C is incorrect because the “Err-disabled recovery after port-security shutdown” option describes a different concept: After a shutdown-mode port-security violation, the interface is typically error-disabled until the condition is corrected and the interface is recovered manually or by configured recovery.

Answer D is incorrect because the “Port security” option describes a different concept: a switch feature that restricts which source MAC addresses are allowed on an access port.

 

Question 10

Which default port-security violation mode places the interface into an error-disabled state after a violation?

  1. Shutdown violation mode
  2. Port-security aging
  3. Port-security maximum
  4. Port security

Correct Answer: A

 

Correct Answer

Answer A is correct because the selected answer describes the default port-security violation mode that places the interface into an error-disabled state after a violation.

Incorrect Answers

Answer B is incorrect because the “Port-security aging” option describes a different concept: Port-security aging can remove dynamically learned secure MAC addresses after configured conditions or time intervals.

Answer C is incorrect because the “Port-security maximum” option describes a different concept: the port-security maximum setting controls how many secure MAC addresses are permitted on an interface.

Answer D is incorrect because the “Port security” option describes a different concept: a switch feature that restricts which source MAC addresses are allowed on an access port.

 

Question 11

An access port must permit no more than a configured number of secure MAC addresses. Which port-security setting controls this limit?

  1. Err-disabled recovery after port-security shutdown
  2. Port-security maximum
  3. Sticky MAC
  4. Port-security aging

Correct Answer: B

 

Correct Answer

Answer B is correct because the selected answer describes the port-security maximum setting controls how many secure MAC addresses are permitted on an interface.

Incorrect Answers

Answer A is incorrect because the “Err-disabled recovery after port-security shutdown” option describes a different concept: After a shutdown-mode port-security violation, the interface is typically error-disabled until the condition is corrected and the interface is recovered manually or by configured recovery.

Answer C is incorrect because the “Sticky MAC” option describes a different concept: a port-security feature that dynamically learns secure MAC addresses and adds them to the running configuration.

Answer D is incorrect because the “Port-security aging” option describes a different concept: Port-security aging can remove dynamically learned secure MAC addresses after configured conditions or time intervals.

 

Question 12

A port-security design must remove eligible learned secure addresses after configured aging conditions or intervals. Which feature manages this removal?

  1. Sticky MAC
  2. Shutdown violation mode
  3. Port-security aging
  4. Secure MAC address

Correct Answer: C

 

Correct Answer

Answer C is correct because Port-security aging can remove dynamically learned secure MAC addresses after configured conditions or time intervals.

Incorrect Answers

Answer A is incorrect because the “Sticky MAC” option describes a different concept: a port-security feature that dynamically learns secure MAC addresses and adds them to the running configuration.

Answer B is incorrect because the “Shutdown violation mode” option describes a different concept: the default port-security violation mode that places the interface into an error-disabled state after a violation.

Answer D is incorrect because the “Secure MAC address” option describes a different concept: a secure MAC address is a source MAC address explicitly or dynamically permitted by port security on an interface.

 

Question 13

What is a source MAC address permitted explicitly or dynamically by port security on an interface called?

  1. Port-security aging
  2. Secure MAC address
  3. Shutdown violation mode
  4. Port security

Correct Answer: B

 

Correct Answer

Answer B is correct because the selected answer describes a secure MAC address is a source MAC address explicitly or dynamically permitted by port security on an interface.

Incorrect Answers

Answer A is incorrect because the “Port-security aging” option describes a different concept: Port-security aging can remove dynamically learned secure MAC addresses after configured conditions or time intervals.

Answer C is incorrect because the “Shutdown violation mode” option describes a different concept: the default port-security violation mode that places the interface into an error-disabled state after a violation.

Answer D is incorrect because the “Port security” option describes a different concept: a switch feature that restricts which source MAC addresses are allowed on an access port.

 

Question 14

Which term describes after a shutdown-mode port-security violation, the interface is typically error-disabled until the condition is corrected and the interface is recovered manually or by configured recovery?

  1. Err-disabled recovery after port-security shutdown
  2. Shutdown violation mode
  3. Secure MAC address
  4. Port-security maximum

Correct Answer: A

 

Correct Answer

Answer A is correct because After a shutdown-mode port-security violation, the interface is typically error-disabled until the condition is corrected and the interface is recovered manually or by configured recovery.

Incorrect Answers

Answer B is incorrect because the “Shutdown violation mode” option describes a different concept: the default port-security violation mode that places the interface into an error-disabled state after a violation.

Answer C is incorrect because the “Secure MAC address” option describes a different concept: a secure MAC address is a source MAC address explicitly or dynamically permitted by port security on an interface.

Answer D is incorrect because the “Port-security maximum” option describes a different concept: the port-security maximum setting controls how many secure MAC addresses are permitted on an interface.

 

Question 15

Dynamic ARP Inspection can validate hosts against trusted client bindings learned during DHCP operation. Which database holds these bindings?

  1. DHCP snooping rate limiting
  2. DAI trusted port
  3. DHCP snooping database
  4. DHCP snooping

Correct Answer: C

 

Correct Answer

Answer C is correct because the selected answer describes the DHCP snooping database stores trusted client bindings that can be used by other security features such as Dynamic ARP Inspection.

Incorrect Answers

Answer A is incorrect because the “DHCP snooping rate limiting” option describes a different concept: DHCP snooping can rate-limit DHCP messages on untrusted ports to reduce abuse and denial-of-service behavior.

Answer B is incorrect because the “DAI trusted port” option describes a different concept: a trusted Dynamic ARP Inspection port bypasses normal ARP validation and is typically reserved for carefully controlled infrastructure links.

Answer D is incorrect because the “DHCP snooping” option describes a different concept: a Layer 2 security feature that filters DHCP messages and builds a binding table from legitimate DHCP assignments.

 

Question 16

A host floods an untrusted switch port with DHCP messages. Which specific DHCP snooping capability limits the rate of these messages?

  1. Untrusted DHCP snooping port
  2. DHCP snooping rate limiting
  3. Dynamic ARP Inspection
  4. DHCP snooping

Correct Answer: B

 

Correct Answer

Answer B is correct because DHCP snooping can rate-limit DHCP messages on untrusted ports to reduce abuse and denial-of-service behavior.

Incorrect Answers

Answer A is incorrect because the “Untrusted DHCP snooping port” option describes a different concept: a switch port on which DHCP server messages are normally rejected to help block rogue DHCP servers.

Answer C is incorrect because the “Dynamic ARP Inspection” option describes a different concept: a switch security feature that validates ARP messages against trusted information such as the DHCP snooping database.

Answer D is incorrect because the “DHCP snooping” option describes a different concept: a Layer 2 security feature that filters DHCP messages and builds a binding table from legitimate DHCP assignments.

 

Question 17

What is a trusted Dynamic ARP Inspection port bypasses normal ARP validation and is typically reserved for carefully controlled infrastructure links?

  1. DHCP snooping database
  2. Dynamic ARP Inspection
  3. Trusted DHCP snooping port
  4. DAI trusted port

Correct Answer: D

 

Correct Answer

Answer D is correct because the selected answer describes a trusted Dynamic ARP Inspection port bypasses normal ARP validation and is typically reserved for carefully controlled infrastructure links.

Incorrect Answers

Answer A is incorrect because the “DHCP snooping database” option describes a different concept: the DHCP snooping database stores trusted client bindings that can be used by other security features such as Dynamic ARP Inspection.

Answer B is incorrect because the “Dynamic ARP Inspection” option describes a different concept: a switch security feature that validates ARP messages against trusted information such as the DHCP snooping database.

Answer C is incorrect because the “Trusted DHCP snooping port” option describes a different concept: a switch port allowed to send DHCP server messages such as Offer and ACK messages.

 

Question 18

Which term describes dynamic ARP Inspection checks ARP information against trusted bindings or configured ARP information to detect spoofed ARP messages?

  1. Dynamic ARP Inspection
  2. DHCP snooping binding table
  3. DHCP snooping
  4. DAI validation

Correct Answer: D

 

Correct Answer

Answer D is correct because Dynamic ARP Inspection checks ARP information against trusted bindings or configured ARP information to detect spoofed ARP messages.

Incorrect Answers

Answer A is incorrect because the “Dynamic ARP Inspection” option describes a different concept: a switch security feature that validates ARP messages against trusted information such as the DHCP snooping database.

Answer B is incorrect because the “DHCP snooping binding table” option describes a different concept: a table that records legitimate client MAC, IP, VLAN, port, and lease information learned from DHCP.

Answer C is incorrect because the “DHCP snooping” option describes a different concept: a Layer 2 security feature that filters DHCP messages and builds a binding table from legitimate DHCP assignments.

 

Question 19

An unauthorized server gives clients incorrect DHCP addressing and gateway information. What is this server commonly called?

  1. ARP spoofing
  2. DHCP snooping
  3. Trusted DHCP snooping port
  4. Rogue DHCP server

Correct Answer: D

 

Correct Answer

Answer D is correct because the selected answer describes a rogue DHCP server is an unauthorized DHCP server that can provide incorrect addressing or gateway information to clients.

Incorrect Answers

Answer A is incorrect because the “ARP spoofing” option describes a different concept: ARP spoofing uses falsified ARP information to associate an attacker-controlled MAC address with another host or gateway IP address.

Answer B is incorrect because the “DHCP snooping” option describes a different concept: a Layer 2 security feature that filters DHCP messages and builds a binding table from legitimate DHCP assignments.

Answer C is incorrect because the “Trusted DHCP snooping port” option describes a different concept: a switch port allowed to send DHCP server messages such as Offer and ACK messages.

 

Question 20

An attacker advertises false ARP information to associate the attacker’s MAC address with the gateway’s IP address. Which attack is being performed?

  1. Port-security aging
  2. Rogue DHCP server
  3. ARP spoofing
  4. Dynamic ARP Inspection

Correct Answer: C

 

Correct Answer

Answer C is correct because ARP spoofing uses falsified ARP information to associate an attacker-controlled MAC address with another host or gateway IP address.

Incorrect Answers

Answer A is incorrect because the “Port-security aging” option describes a different concept: Port-security aging can remove dynamically learned secure MAC addresses after configured conditions or time intervals.

Answer B is incorrect because the “Rogue DHCP server” option describes a different concept: a rogue DHCP server is an unauthorized DHCP server that can provide incorrect addressing or gateway information to clients.

Answer D is incorrect because the “Dynamic ARP Inspection” option describes a different concept: a switch security feature that validates ARP messages against trusted information such as the DHCP snooping database.

 

Question 21

For DHCP snooping, which statement is accurate?

  1. DHCP snooping can rate-limit DHCP messages on untrusted ports to reduce abuse and denial-of-service behavior.
  2. A switch security feature that validates ARP messages against trusted information such as the DHCP snooping database.
  3. A Layer 2 security feature that filters DHCP messages and builds a binding table from legitimate DHCP assignments.
  4. The DHCP snooping database stores trusted client bindings that can be used by other security features such as Dynamic ARP Inspection.

Correct Answer: C

 

Correct Answer

Answer C is correct because the selected answer describes a Layer 2 security feature that filters DHCP messages and builds a binding table from legitimate DHCP assignments.

Incorrect Answers

Answer A is incorrect because the “DHCP snooping rate limiting” option describes a different concept: DHCP snooping can rate-limit DHCP messages on untrusted ports to reduce abuse and denial-of-service behavior.

Answer B is incorrect because the “Dynamic ARP Inspection” option describes a different concept: a switch security feature that validates ARP messages against trusted information such as the DHCP snooping database.

Answer D is incorrect because the “DHCP snooping database” option describes a different concept: the DHCP snooping database stores trusted client bindings that can be used by other security features such as Dynamic ARP Inspection.

 

Question 22

For Trusted DHCP snooping port, which statement is accurate?

  1. A switch port allowed to send DHCP server messages such as Offer and ACK messages.
  2. A switch port on which DHCP server messages are normally rejected to help block rogue DHCP servers.
  3. A table that records legitimate client MAC, IP, VLAN, port, and lease information learned from DHCP.
  4. A switch feature that restricts which source MAC addresses are allowed on an access port.

Correct Answer: A

 

Correct Answer

Answer A is correct because the selected answer describes a switch port allowed to send DHCP server messages such as Offer and ACK messages.

Incorrect Answers

Answer B is incorrect because the “Untrusted DHCP snooping port” option describes a different concept: a switch port on which DHCP server messages are normally rejected to help block rogue DHCP servers.

Answer C is incorrect because the “DHCP snooping binding table” option describes a different concept: a table that records legitimate client MAC, IP, VLAN, port, and lease information learned from DHCP.

Answer D is incorrect because the “Port security” option describes a different concept: a switch feature that restricts which source MAC addresses are allowed on an access port.

 

Question 23

For Untrusted DHCP snooping port, which statement is accurate?

  1. A table that records legitimate client MAC, IP, VLAN, port, and lease information learned from DHCP.
  2. A switch feature that restricts which source MAC addresses are allowed on an access port.
  3. A switch port allowed to send DHCP server messages such as Offer and ACK messages.
  4. A switch port on which DHCP server messages are normally rejected to help block rogue DHCP servers.

Correct Answer: D

 

Correct Answer

Answer D is correct because it accurately defines Untrusted DHCP snooping port. The matching definition is: A switch port on which DHCP server messages are normally rejected to help block rogue DHCP servers.

Incorrect Answers

Answer A is incorrect because the “DHCP snooping binding table” option describes a different concept: a table that records legitimate client MAC, IP, VLAN, port, and lease information learned from DHCP.

Answer B is incorrect because the “Port security” option describes a different concept: a switch feature that restricts which source MAC addresses are allowed on an access port.

Answer C is incorrect because the “Trusted DHCP snooping port” option describes a different concept: a switch port allowed to send DHCP server messages such as Offer and ACK messages.

 

Question 24

For DHCP snooping binding table, which statement is accurate?

  1. A Layer 2 security feature that filters DHCP messages and builds a binding table from legitimate DHCP assignments.
  2. A switch port on which DHCP server messages are normally rejected to help block rogue DHCP servers.
  3. The DHCP snooping database stores trusted client bindings that can be used by other security features such as Dynamic ARP Inspection.
  4. A table that records legitimate client MAC, IP, VLAN, port, and lease information learned from DHCP.

Correct Answer: D

 

Correct Answer

Answer D is correct because the choice accurately describes DHCP snooping binding table: A table that records legitimate client MAC, IP, VLAN, port, and lease information learned from DHCP.

Incorrect Answers

Answer A is incorrect because the “DHCP snooping” option describes a different concept: a Layer 2 security feature that filters DHCP messages and builds a binding table from legitimate DHCP assignments.

Answer B is incorrect because the “Untrusted DHCP snooping port” option describes a different concept: a switch port on which DHCP server messages are normally rejected to help block rogue DHCP servers.

Answer C is incorrect because the “DHCP snooping database” option describes a different concept: the DHCP snooping database stores trusted client bindings that can be used by other security features such as Dynamic ARP Inspection.

 

Question 25

For Dynamic ARP Inspection, which statement is accurate?

  1. A switch security feature that validates ARP messages against trusted information such as the DHCP snooping database.
  2. A trusted Dynamic ARP Inspection port bypasses normal ARP validation and is typically reserved for carefully controlled infrastructure links.
  3. Dynamic ARP Inspection checks ARP information against trusted bindings or configured ARP information to detect spoofed ARP messages.
  4. A switch port allowed to send DHCP server messages such as Offer and ACK messages.

Correct Answer: A

 

Correct Answer

Answer A is correct because the selected answer describes a switch security feature that validates ARP messages against trusted information such as the DHCP snooping database.

Incorrect Answers

Answer B is incorrect because the “DAI trusted port” option describes a different concept: a trusted Dynamic ARP Inspection port bypasses normal ARP validation and is typically reserved for carefully controlled infrastructure links.

Answer C is incorrect because the “DAI validation” option describes a different concept: Dynamic ARP Inspection checks ARP information against trusted bindings or configured ARP information to detect spoofed ARP messages.

Answer D is incorrect because the “Trusted DHCP snooping port” option describes a different concept: a switch port allowed to send DHCP server messages such as Offer and ACK messages.

 

Question 26

For Port security, which statement is accurate?

  1. A switch feature that restricts which source MAC addresses are allowed on an access port.
  2. The port-security maximum setting controls how many secure MAC addresses are permitted on an interface.
  3. A switch port on which DHCP server messages are normally rejected to help block rogue DHCP servers.
  4. Port-security aging can remove dynamically learned secure MAC addresses after configured conditions or time intervals.

Correct Answer: A

 

Correct Answer

Answer A is correct because the selected answer describes a switch feature that restricts which source MAC addresses are allowed on an access port.

Incorrect Answers

Answer B is incorrect because the “Port-security maximum” option describes a different concept: the port-security maximum setting controls how many secure MAC addresses are permitted on an interface.

Answer C is incorrect because the “Untrusted DHCP snooping port” option describes a different concept: a switch port on which DHCP server messages are normally rejected to help block rogue DHCP servers.

Answer D is incorrect because the “Port-security aging” option describes a different concept: Port-security aging can remove dynamically learned secure MAC addresses after configured conditions or time intervals.

 

Question 27

For Sticky MAC, which statement is accurate?

  1. The default port-security violation mode that places the interface into an error-disabled state after a violation.
  2. The port-security maximum setting controls how many secure MAC addresses are permitted on an interface.
  3. A port-security feature that dynamically learns secure MAC addresses and adds them to the running configuration.
  4. A port-security mode that drops unauthorized frames and increments/logs violations while keeping the port up.

Correct Answer: C

 

Correct Answer

Answer C is correct because it accurately defines Sticky MAC. The matching definition is: A port-security feature that dynamically learns secure MAC addresses and adds them to the running configuration.

Incorrect Answers

Answer A is incorrect because the “Shutdown violation mode” option describes a different concept: the default port-security violation mode that places the interface into an error-disabled state after a violation.

Answer B is incorrect because the “Port-security maximum” option describes a different concept: the port-security maximum setting controls how many secure MAC addresses are permitted on an interface.

Answer D is incorrect because the “Restrict violation mode” option describes a different concept: a port-security mode that drops unauthorized frames and increments/logs violations while keeping the port up.

 

Question 28

For Protect violation mode, which statement is accurate?

  1. The default port-security violation mode that places the interface into an error-disabled state after a violation.
  2. A port-security mode that drops unauthorized frames and increments/logs violations while keeping the port up.
  3. A port-security mode that drops frames from unauthorized MAC addresses without shutting the port down.
  4. After a shutdown-mode port-security violation, the interface is typically error-disabled until the condition is corrected and the interface is recovered manually or by configured recovery.

Correct Answer: C

 

Correct Answer

Answer C is correct because the choice accurately describes Protect violation mode: A port-security mode that drops frames from unauthorized MAC addresses without shutting the port down.

Incorrect Answers

Answer A is incorrect because the “Shutdown violation mode” option describes a different concept: the default port-security violation mode that places the interface into an error-disabled state after a violation.

Answer B is incorrect because the “Restrict violation mode” option describes a different concept: a port-security mode that drops unauthorized frames and increments/logs violations while keeping the port up.

Answer D is incorrect because the “Err-disabled recovery after port-security shutdown” option describes a different concept: After a shutdown-mode port-security violation, the interface is typically error-disabled until the condition is corrected and the interface is recovered manually or by configured recovery.

 

Question 29

For Restrict violation mode, which statement is accurate?

  1. After a shutdown-mode port-security violation, the interface is typically error-disabled until the condition is corrected and the interface is recovered manually or by configured recovery.
  2. The port-security maximum setting controls how many secure MAC addresses are permitted on an interface.
  3. A port-security mode that drops unauthorized frames and increments/logs violations while keeping the port up.
  4. Port-security aging can remove dynamically learned secure MAC addresses after configured conditions or time intervals.

Correct Answer: C

 

Correct Answer

Answer C is correct because the selected answer describes a port-security mode that drops unauthorized frames and increments/logs violations while keeping the port up.

Incorrect Answers

Answer A is incorrect because the “Err-disabled recovery after port-security shutdown” option describes a different concept: After a shutdown-mode port-security violation, the interface is typically error-disabled until the condition is corrected and the interface is recovered manually or by configured recovery.

Answer B is incorrect because the “Port-security maximum” option describes a different concept: the port-security maximum setting controls how many secure MAC addresses are permitted on an interface.

Answer D is incorrect because the “Port-security aging” option describes a different concept: Port-security aging can remove dynamically learned secure MAC addresses after configured conditions or time intervals.

 

Question 30

For Shutdown violation mode, which statement is accurate?

  1. A secure MAC address is a source MAC address explicitly or dynamically permitted by port security on an interface.
  2. The default port-security violation mode that places the interface into an error-disabled state after a violation.
  3. The port-security maximum setting controls how many secure MAC addresses are permitted on an interface.
  4. A port-security mode that drops frames from unauthorized MAC addresses without shutting the port down.

Correct Answer: B

 

Correct Answer

Answer B is correct because the selected answer describes the default port-security violation mode that places the interface into an error-disabled state after a violation.

Incorrect Answers

Answer A is incorrect because the “Secure MAC address” option describes a different concept: a secure MAC address is a source MAC address explicitly or dynamically permitted by port security on an interface.

Answer C is incorrect because the “Port-security maximum” option describes a different concept: the port-security maximum setting controls how many secure MAC addresses are permitted on an interface.

Answer D is incorrect because the “Protect violation mode” option describes a different concept: a port-security mode that drops frames from unauthorized MAC addresses without shutting the port down.

 

Question 31

For Port-security maximum, which statement is accurate?

  1. A table that records legitimate client MAC, IP, VLAN, port, and lease information learned from DHCP.
  2. A port-security mode that drops frames from unauthorized MAC addresses without shutting the port down.
  3. A switch feature that restricts which source MAC addresses are allowed on an access port.
  4. The port-security maximum setting controls how many secure MAC addresses are permitted on an interface.

Correct Answer: D

 

Correct Answer

Answer D is correct because it accurately defines Port-security maximum. The matching definition is: The port-security maximum setting controls how many secure MAC addresses are permitted on an interface.

Incorrect Answers

Answer A is incorrect because the “DHCP snooping binding table” option describes a different concept: a table that records legitimate client MAC, IP, VLAN, port, and lease information learned from DHCP.

Answer B is incorrect because the “Protect violation mode” option describes a different concept: a port-security mode that drops frames from unauthorized MAC addresses without shutting the port down.

Answer C is incorrect because the “Port security” option describes a different concept: a switch feature that restricts which source MAC addresses are allowed on an access port.

 

Question 32

For Port-security aging, which statement is accurate?

  1. Port-security aging can remove dynamically learned secure MAC addresses after configured conditions or time intervals.
  2. A table that records legitimate client MAC, IP, VLAN, port, and lease information learned from DHCP.
  3. The default port-security violation mode that places the interface into an error-disabled state after a violation.
  4. A port-security feature that dynamically learns secure MAC addresses and adds them to the running configuration.

Correct Answer: A

 

Correct Answer

Answer A is correct because the choice accurately describes Port-security aging: Port-security aging can remove dynamically learned secure MAC addresses after configured conditions or time intervals.

Incorrect Answers

Answer B is incorrect because the “DHCP snooping binding table” option describes a different concept: a table that records legitimate client MAC, IP, VLAN, port, and lease information learned from DHCP.

Answer C is incorrect because the “Shutdown violation mode” option describes a different concept: the default port-security violation mode that places the interface into an error-disabled state after a violation.

Answer D is incorrect because the “Sticky MAC” option describes a different concept: a port-security feature that dynamically learns secure MAC addresses and adds them to the running configuration.

 

Question 33

For Secure MAC address, which statement is accurate?

  1. A secure MAC address is a source MAC address explicitly or dynamically permitted by port security on an interface.
  2. A switch feature that restricts which source MAC addresses are allowed on an access port.
  3. The port-security maximum setting controls how many secure MAC addresses are permitted on an interface.
  4. A port-security mode that drops unauthorized frames and increments/logs violations while keeping the port up.

Correct Answer: A

 

Correct Answer

Answer A is correct because the selected answer describes a secure MAC address is a source MAC address explicitly or dynamically permitted by port security on an interface.

Incorrect Answers

Answer B is incorrect because the “Port security” option describes a different concept: a switch feature that restricts which source MAC addresses are allowed on an access port.

Answer C is incorrect because the “Port-security maximum” option describes a different concept: the port-security maximum setting controls how many secure MAC addresses are permitted on an interface.

Answer D is incorrect because the “Restrict violation mode” option describes a different concept: a port-security mode that drops unauthorized frames and increments/logs violations while keeping the port up.

 

Question 34

For Err-disabled recovery after port-security shutdown, which statement is accurate?

  1. A port-security feature that dynamically learns secure MAC addresses and adds them to the running configuration.
  2. The default port-security violation mode that places the interface into an error-disabled state after a violation.
  3. The port-security maximum setting controls how many secure MAC addresses are permitted on an interface.
  4. After a shutdown-mode port-security violation, the interface is typically error-disabled until the condition is corrected and the interface is recovered manually or by configured recovery.

Correct Answer: D

 

Correct Answer

Answer D is correct because After a shutdown-mode port-security violation, the interface is typically error-disabled until the condition is corrected and the interface is recovered manually or by configured recovery.

Incorrect Answers

Answer A is incorrect because the “Sticky MAC” option describes a different concept: a port-security feature that dynamically learns secure MAC addresses and adds them to the running configuration.

Answer B is incorrect because the “Shutdown violation mode” option describes a different concept: the default port-security violation mode that places the interface into an error-disabled state after a violation.

Answer C is incorrect because the “Port-security maximum” option describes a different concept: the port-security maximum setting controls how many secure MAC addresses are permitted on an interface.

 

Question 35

Dynamic ARP Inspection needs trusted DHCP client information. Which statement explains how the DHCP snooping database supports that check?

  1. DHCP snooping can rate-limit DHCP messages on untrusted ports to reduce abuse and denial-of-service behavior.
  2. The DHCP snooping database stores trusted client bindings that can be used by other security features such as Dynamic ARP Inspection.
  3. Dynamic ARP Inspection checks ARP information against trusted bindings or configured ARP information to detect spoofed ARP messages.
  4. A switch port on which DHCP server messages are normally rejected to help block rogue DHCP servers.

Correct Answer: B

 

Correct Answer

Answer B is correct because it accurately defines DHCP snooping database. The matching definition is: The DHCP snooping database stores trusted client bindings that can be used by other security features such as Dynamic ARP Inspection.

Incorrect Answers

Answer A is incorrect because the “DHCP snooping rate limiting” option describes a different concept: DHCP snooping can rate-limit DHCP messages on untrusted ports to reduce abuse and denial-of-service behavior.

Answer C is incorrect because the “DAI validation” option describes a different concept: Dynamic ARP Inspection checks ARP information against trusted bindings or configured ARP information to detect spoofed ARP messages.

Answer D is incorrect because the “Untrusted DHCP snooping port” option describes a different concept: a switch port on which DHCP server messages are normally rejected to help block rogue DHCP servers.

 

Question 36

For DHCP snooping rate limiting, which statement is accurate?

  1. Dynamic ARP Inspection checks ARP information against trusted bindings or configured ARP information to detect spoofed ARP messages.
  2. A rogue DHCP server is an unauthorized DHCP server that can provide incorrect addressing or gateway information to clients.
  3. A Layer 2 security feature that filters DHCP messages and builds a binding table from legitimate DHCP assignments.
  4. DHCP snooping can rate-limit DHCP messages on untrusted ports to reduce abuse and denial-of-service behavior.

Correct Answer: D

 

Correct Answer

Answer D is correct because the choice accurately describes DHCP snooping rate limiting: DHCP snooping can rate-limit DHCP messages on untrusted ports to reduce abuse and denial-of-service behavior.

Incorrect Answers

Answer A is incorrect because the “DAI validation” option describes a different concept: Dynamic ARP Inspection checks ARP information against trusted bindings or configured ARP information to detect spoofed ARP messages.

Answer B is incorrect because the “Rogue DHCP server” option describes a different concept: a rogue DHCP server is an unauthorized DHCP server that can provide incorrect addressing or gateway information to clients.

Answer C is incorrect because the “DHCP snooping” option describes a different concept: a Layer 2 security feature that filters DHCP messages and builds a binding table from legitimate DHCP assignments.

 

Question 37

For DAI trusted port, which statement is accurate?

  1. Dynamic ARP Inspection checks ARP information against trusted bindings or configured ARP information to detect spoofed ARP messages.
  2. A trusted Dynamic ARP Inspection port bypasses normal ARP validation and is typically reserved for carefully controlled infrastructure links.
  3. A switch port allowed to send DHCP server messages such as Offer and ACK messages.
  4. ARP spoofing uses falsified ARP information to associate an attacker-controlled MAC address with another host or gateway IP address.

Correct Answer: B

 

Correct Answer

Answer B is correct because the selected answer describes a trusted Dynamic ARP Inspection port bypasses normal ARP validation and is typically reserved for carefully controlled infrastructure links.

Incorrect Answers

Answer A is incorrect because the “DAI validation” option describes a different concept: Dynamic ARP Inspection checks ARP information against trusted bindings or configured ARP information to detect spoofed ARP messages.

Answer C is incorrect because the “Trusted DHCP snooping port” option describes a different concept: a switch port allowed to send DHCP server messages such as Offer and ACK messages.

Answer D is incorrect because the “ARP spoofing” option describes a different concept: ARP spoofing uses falsified ARP information to associate an attacker-controlled MAC address with another host or gateway IP address.

 

Question 38

For DAI validation, which statement is accurate?

  1. ARP spoofing uses falsified ARP information to associate an attacker-controlled MAC address with another host or gateway IP address.
  2. Dynamic ARP Inspection checks ARP information against trusted bindings or configured ARP information to detect spoofed ARP messages.
  3. A Layer 2 security feature that filters DHCP messages and builds a binding table from legitimate DHCP assignments.
  4. A switch security feature that validates ARP messages against trusted information such as the DHCP snooping database.

Correct Answer: B

 

Correct Answer

Answer B is correct because Dynamic ARP Inspection checks ARP information against trusted bindings or configured ARP information to detect spoofed ARP messages.

Incorrect Answers

Answer A is incorrect because the “ARP spoofing” option describes a different concept: ARP spoofing uses falsified ARP information to associate an attacker-controlled MAC address with another host or gateway IP address.

Answer C is incorrect because the “DHCP snooping” option describes a different concept: a Layer 2 security feature that filters DHCP messages and builds a binding table from legitimate DHCP assignments.

Answer D is incorrect because the “Dynamic ARP Inspection” option describes a different concept: a switch security feature that validates ARP messages against trusted information such as the DHCP snooping database.

 

Question 39

For Rogue DHCP server, which statement is accurate?

  1. A rogue DHCP server is an unauthorized DHCP server that can provide incorrect addressing or gateway information to clients.
  2. DHCP snooping can rate-limit DHCP messages on untrusted ports to reduce abuse and denial-of-service behavior.
  3. A table that records legitimate client MAC, IP, VLAN, port, and lease information learned from DHCP.
  4. A switch security feature that validates ARP messages against trusted information such as the DHCP snooping database.

Correct Answer: A

 

Correct Answer

Answer A is correct because it accurately defines Rogue DHCP server. The matching definition is: A rogue DHCP server is an unauthorized DHCP server that can provide incorrect addressing or gateway information to clients.

Incorrect Answers

Answer B is incorrect because the “DHCP snooping rate limiting” option describes a different concept: DHCP snooping can rate-limit DHCP messages on untrusted ports to reduce abuse and denial-of-service behavior.

Answer C is incorrect because the “DHCP snooping binding table” option describes a different concept: a table that records legitimate client MAC, IP, VLAN, port, and lease information learned from DHCP.

Answer D is incorrect because the “Dynamic ARP Inspection” option describes a different concept: a switch security feature that validates ARP messages against trusted information such as the DHCP snooping database.

 

Question 40

For ARP spoofing, which statement is accurate?

  1. A secure MAC address is a source MAC address explicitly or dynamically permitted by port security on an interface.
  2. ARP spoofing uses falsified ARP information to associate an attacker-controlled MAC address with another host or gateway IP address.
  3. A trusted Dynamic ARP Inspection port bypasses normal ARP validation and is typically reserved for carefully controlled infrastructure links.
  4. The port-security maximum setting controls how many secure MAC addresses are permitted on an interface.

Correct Answer: B

 

Correct Answer

Answer B is correct because the choice accurately describes ARP spoofing: ARP spoofing uses falsified ARP information to associate an attacker-controlled MAC address with another host or gateway IP address.

Incorrect Answers

Answer A is incorrect because the “Secure MAC address” option describes a different concept: a secure MAC address is a source MAC address explicitly or dynamically permitted by port security on an interface.

Answer C is incorrect because the “DAI trusted port” option describes a different concept: a trusted Dynamic ARP Inspection port bypasses normal ARP validation and is typically reserved for carefully controlled infrastructure links.

Answer D is incorrect because the “Port-security maximum” option describes a different concept: the port-security maximum setting controls how many secure MAC addresses are permitted on an interface.

img