Soru

Zorluk: OrtaLayer 2 Security Features (Port Security, DHCP Snooping, DAI)

A network administrator is implementing Layer 2 security controls on an access switch, configuring Port Security with sticky MAC address learning alongside DHCP Snooping on edge switch ports. Which two statements correctly describe the operational behavior of these features? (Select two.)

  1. Dynamically learned sticky MAC addresses are added directly to the running configuration in RAM.Cevap
  2. DHCP server response messages, such as DHCPOFFER and DHCPACK, are dropped when received on an untrusted port.Cevap
  3. C
    Sticky MAC addresses added to the running configuration automatically persist in NVRAM across switch reboots without saving.
  4. D
    Enabling DHCP Snooping automatically overrides native VLAN mismatch errors on 802.1Q trunk links.

Cevap

The correct answers state that dynamically learned sticky MAC addresses are appended to the running configuration in RAM, and that DHCP server messages (such as DHCPOFFER and DHCPACK) arriving on untrusted ports are dropped by DHCP Snooping.
When port security sticky learning is configured, learned MAC addresses are converted into static-like MAC entries directly in the running-config in active RAM. Additionally, DHCP Snooping enforces boundary security by designating access interfaces as untrusted by default, dropping any DHCP server messages (such as DHCPACK or DHCPOFFER) that attempt to enter an untrusted interface.

Adım Adım Çözüm

1
Analyze Port Security sticky MAC behavior
Confirm that sticky MAC learning dynamically populates the running configuration in RAM, which requires a manual save to startup configuration to persist across reboots.
Sticky MAC addresses act as static entries in running-config, but RAM is volatile memory.
2
Analyze DHCP Snooping port trust rules
Confirm that untrusted ports are only permitted to send DHCP requests from clients, while server responses (DHCPACK, DHCPOFFER) are intercepted and dropped.
Untrusted ports represent client-facing links, preventing rogue DHCP servers from handing out invalid addresses.

Anahtar Kavram

Port Security Sticky MAC Persistence and DHCP Snooping Trust Verification
Bu soruyu puanla