exam questions

Exam 400-007 All Questions

View all questions & answers for the 400-007 exam

Exam 400-007 topic 1 question 140 discussion

Actual exam question from Cisco's 400-007
Question #: 140
Topic #: 1
[All 400-007 Questions]

Which technology supports antispoofing and does not have any impact on encryption performance regardless of packet size?

  • A. MACsec
  • B. IP source guard
  • C. DHCP snooping with DAI
  • D. IPsec
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
4f873c4
1 month, 3 weeks ago
Selected Answer: A
The correct answer is A
upvoted 1 times
...
blurain
9 months, 1 week ago
Selected Answer: A
Cisco might be fishing for the MACsec answer as data is encrypted and traffic not being prone to spoofing attacks.
upvoted 4 times
...
Rollizo
9 months, 3 weeks ago
Selected Answer: A
Macsec provides anti spoofing and encryption. IP source guard not
upvoted 2 times
...
dvthakore
11 months, 1 week ago
Selected Answer: B
Security breaches can occur at any layer of the OSI model. At Layer 2, some of the common breaches are MAC address spoofing, ARP spoofing, Denial of Service (DoS) attacks against a DHCP server, and VLAN hopping. Hence, MACSec protects against ARP & MAC Spoofing.
upvoted 1 times
Rollizo
9 months, 3 weeks ago
Then you mean A is the right one
upvoted 1 times
...
...
J_W
1 year, 5 months ago
Selected Answer: B
IP source guard is a security feature that prevents IP spoofing attacks by filtering traffic based on the source IP addresses in the IP header. It ensures that the source IP addresses in the incoming packets are legitimate and associated with the correct interfaces. IP source guard does not have any impact on encryption performance and operates at the network layer (Layer 3) of the OSI model.
upvoted 2 times
...
bdp123
1 year, 5 months ago
Selected Answer: B
MACsec does not provide any protection for the IP layer or above, which means that it does not prevent attacks such as IP spoofing, denial-of-service, or application-level exploits. https://www.linkedin.com/advice/0/what-pros-cons-using-macsec-lan-wan-security-skills-lan-wan#:~:text=Moreover%2C%20MACsec%20does%20not%20provide%20any%20protection%20for,such%20as%20IP%20spoofing%2C%20denial-of-service%2C%20or%20application-level%20exploits.
upvoted 1 times
bdp123
1 year, 5 months ago
Actually, if the question is referring to mac address spoofing, then yes 'A' is correct. They should clarify if IP address anti spoofing or mac address spoofing. At Layer 2, some of the common breaches are MAC address spoofing, ARP spoofing, Denial of Service (DoS) attacks against a DHCP server, and VLAN hopping. https://www.cisco.com/c/en/us/td/docs/iosxr/cisco8000/security/70x/b-system-security-cg-cisco8000-70x/configuring-macsec.html
upvoted 2 times
bdp123
1 year, 5 months ago
Also, macsec is not limited by packet size - MACsec supports line-rate encryption performance (100 Gbps+), regardless of the MTU and packet size https://www.cisco.com/c/dam/en/us/td/docs/solutions/Enterprise/Security/MACsec/WP-High-Speed-WAN-Encrypt-MACsec.pdf
upvoted 2 times
Rollizo
9 months, 3 weeks ago
It is MACSEC, if you protect Ethernet gram, then you protect above layers
upvoted 3 times
...
...
...
...
CastleMagic
1 year, 7 months ago
Selected Answer: B
A is Wrong. MACsec also cannot protect against malicious layer 3 traffic coming from a different network interface, on a machine connected to multiple LANs. For example, attacks that rely on forcing traffic to leave from other interfaces, using ARP spoofing or IP redirects, cannot be prevented using MACsec alone.
upvoted 2 times
...
biddid2
1 year, 7 months ago
Selected Answer: B
A is wrong. If packet size is large, additional fragmentation action affects the encryption performance.
upvoted 1 times
...
gcpengineer
1 year, 8 months ago
Selected Answer: B
Bis the ans. IP source guard is a security feature that helps prevent IP spoofing attacks by allowing only packets with valid source IP addresses to pass through a network device. It uses a combination of source IP address filtering and DHCP snooping to determine the validity of the source IP address.
upvoted 3 times
...
ying162
1 year, 8 months ago
per Cisco documentation: Security breaches can occur at any layer of the OSI model. At Layer 2, some of the common breaches are MAC address spoofing, ARP spoofing, Denial of Service (DoS) attacks against a DHCP server, and VLAN hopping. MACSec secures data on physical media, making it impossible for data to be compromised at higher layers
upvoted 3 times
...
ying162
1 year, 9 months ago
I think it is B
upvoted 1 times
ying162
1 year, 8 months ago
I think macsec is correct because of the encryption requirement. Also macsec protects against man in the middle attack.
upvoted 2 times
...
...
markmark1983
1 year, 9 months ago
I would choose ip source guard , MACsec is not doing any anti spoofing, instead it is only doing encryption
upvoted 3 times
SFXY
1 year, 5 months ago
B. IP Source Guard is a security feature that restricts IP traffic on untrusted Layer 2 ports by filtering traffic based on the DHCP snooping binding database and IP source bindings. It does not provide encryption.
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago