exam questions

Exam 312-50v11 All Questions

View all questions & answers for the 312-50v11 exam

Exam 312-50v11 topic 1 question 114 discussion

Actual exam question from ECCouncil's 312-50v11
Question #: 114
Topic #: 1
[All 312-50v11 Questions]

DHCP snooping is a great solution to prevent rogue DHCP servers on your network. Which security feature on switchers leverages the DHCP snooping database to help prevent man-in-the-middle attacks?

  • A. Spanning tree
  • B. Dynamic ARP Inspection (DAI)
  • C. Port security
  • D. Layer 2 Attack Prevention Protocol (LAPP)
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Scryptic
Highly Voted 2 years, 7 months ago
What is DHCP snooping database? DHCP snooping is a security feature that acts like a firewall between untrusted hosts and trusted DHCP servers. The DHCP snooping feature performs the following activities: • Validates DHCP messages received from untrusted sources and filters out invalid messages. • Overview of Dynamic ARP Inspection Dynamic ARP Inspection (DAI) is a security feature that validates Address Resolution Protocol (ARP) packets in a network. DAI allows a network administrator to intercept, log, and discard ARP packets with invalid MAC address to IP address bindings. This capability protects the network from certain “man-in-the-middle” attacks.
upvoted 24 times
...
Daniel8660
Highly Voted 1 year, 6 months ago
Selected Answer: B
Defend Against ARP Poisoning Implement Dynamic ARP Inspection(DAI) Using DHCP Snooping Binding Table. To validate the ARP packet, the DAI performs IP-address-to-MAC-address binding inspection stored in the DHCP snooping database before forwarding the packet to its destination. If any invalid IP address binds a MAC address, the DAI will discard the ARP packet. (P.1149/1133)
upvoted 6 times
...
ffactor
Most Recent 8 months ago
DHCP Snooping is a layer 2 security technology incorporated into the operating system of a capable network switch that drops DHCP traffic determined to be unacceptable. DHCP Snooping prevents unauthorized (rogue) DHCP servers offering IP addresses to DHCP clients.????
upvoted 1 times
ffactor
8 months ago
Why not D?
upvoted 1 times
ffactor
8 months ago
Switches operate on layer 2.
upvoted 1 times
...
...
...
piccolopersiano
1 year, 1 month ago
pg 1151-3 official doc . So B
upvoted 2 times
...
Grey975
1 year, 9 months ago
DHCP snooping must be enabled before enabling DAI. ergo DAI needs(leverages) DHCP snooping.
upvoted 2 times
...
Urltenm
2 years, 2 months ago
when cisco was born - network problems appear!)))
upvoted 1 times
...
ANDRESCB1988
2 years, 9 months ago
correct
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago