Layer 2 Security Features (Port Security, DHCP Snooping, DAI)
48 soru
Match each Layer 2 security feature or operational scenario on the left to its corresponding switch behavior or implementation detail on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
Following an unexpected reboot of an enterprise access switch, users connected to interface GigabitEthernet1/0/12 report a complete loss of network connectivity. Upon investigation, the network administrator discovers that the dynamically learned MAC address added to the port security table prior to the switch reload is missing, causing the switch to reject traffic from the connected workstation. Which administrative action was omitted prior to the reboot that resulted in the loss of the sticky MAC address?
An enterprise network administrator is deploying Layer 2 security controls across an access switch. The administrator configures DHCP Snooping and Dynamic ARP Inspection (DAI) on VLAN 15 to safeguard clients against rogue DHCP servers and ARP spoofing attacks. Which TWO statements accurately describe the operational requirements and behaviors of Dynamic ARP Inspection (DAI) in this environment?
Geçerli olan tümünü seçin
A network administrator enables Dynamic ARP Inspection (DAI) on VLAN 10 of a Cisco Catalyst switch to mitigate ARP spoofing attacks across the corporate subnet. Although DHCP clients operate without interruption, several critical servers using statically configured IP addresses immediately lose network access. Switch logs indicate that DAI is actively dropping all ARP packets generated by these static servers because their IP-to-MAC bindings do not exist in the DHCP snooping binding database. Which configuration step must be performed to restore network connectivity for the static servers while maintaining DAI protection on VLAN 10?
A network engineer is troubleshooting host connectivity issues on a Cisco Catalyst switch after enabling Dynamic ARP Inspection (DAI) on VLAN 50. Most clients receive their network settings dynamically via DHCP, but a legacy server connected to interface GigabitEthernet1/0/10 uses a static IP address. Because the server's IP-to-MAC mapping is absent from the DHCP snooping binding database, the switch drops all ARP packets originating from GigabitEthernet1/0/10. Which configuration sequence allows ARP traffic from this static server while maintaining active DAI inspection for all other hosts on VLAN 50?
A network administrator is implementing Layer 2 security controls across corporate access switches. Which TWO operational characteristics correctly describe how DHCP Snooping, Dynamic ARP Inspection (DAI), and Port Security function on untrusted interfaces? (Select TWO.)
Geçerli olan tümünü seçin
A network technician enables DHCP Snooping globally and on VLAN 10 using the commands `ip dhcp snooping` and `ip dhcp snooping vlan 10`. However, clients connected to access ports on VLAN 10 are failing to acquire IP addresses from the central DHCP server reachable via trunk interface GigabitEthernet0/1. Which condition accounts for the DHCP packet drops on the switch?
A network administrator configures port security on access interface GigabitEthernet0/1 of a Cisco Catalyst switch by executing `switchport port-security` and `switchport port-security mac-address sticky`. Hosts connect successfully and their MAC addresses are dynamically learned by the switch. However, after an unscheduled switch reboot, the administrator discovers that the dynamically learned MAC addresses were removed and hosts must re-trigger learning. Which operational step was omitted prior to the switch restart?