exam questions

Exam 300-115 All Questions

View all questions & answers for the 300-115 exam

Exam 300-115 topic 2 question 8 discussion

Actual exam question from Cisco's 300-115
Question #: 8
Topic #: 2
[All 300-115 Questions]

A switch is added into the production network to increase port capacity. A network engineer is configuring the switch for DHCP snooping and IP Source Guard, but is unable to configure ip verify source under several of the interfaces. Which option is the cause of the problem?

  • A. The local DHCP server is disabled prior to enabling IP Source Guard.
  • B. The interfaces are configured as Layer 3 using the no switchport command.
  • C. No VLANs exist on the switch and/or the switch is configured in VTP transparent mode.
  • D. The switch is configured for sdm prefer routing as the switched database management template.
  • E. The configured SVIs on the switch have been removed for the associated interfaces.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️
by filtering traffic based on the DHCP snooping binding
IP source guard is a security feature that restricts IP traffic on nonrouted, Layer 2 interfaces database and on manually configured IP source bindings. You can use IP source guard to prevent traffic attacks caused when a host tries to use the IP address of its neighbor.
You can enable IP source guard when DHCP snooping is enabled on an untrusted interface. After IP source guard is enabled on an interface, the switch blocks all
IP traffic received on the interface, except for DHCP packets allowed by DHCP snooping. A port access control list (ACL) is applied to the interface. The port ACL allows only IP traffic with a source IP address in the IP source binding table and denies all other traffic.
The IP source binding table has bindings that are learned by DHCP snooping or are manually configured (static IP source bindings). An entry in this table has an
IP address, its associated MAC address, and its associated VLAN number. The switch uses the IP source binding table only when IP source guard is enabled.
You can configure IP source guard with source IP address filtering or
IP source guard is supported only on Layer 2 ports, including access and trunk ports. with source IP and MAC address filtering.
Reference: http://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst3550/software/release/12-2_25_see/configuration/guide/3550SCG/ swdhcp82.html#wp1069615

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Currently there are no comments in this discussion, be the first to comment!
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...