CCNA Plan

CCNA practice question: Security Fundamentals

Security FundamentalsDifficulty 2/5

Which feature prevents a rogue DHCP server on an access port from handing out addresses?

  1. ADHCP snooping
  2. BDynamic ARP inspection
  3. CBPDU Guard
  4. DPort security
Show answer and rationale

Correct: A. DHCP snooping drops DHCP server messages (Offer/Ack) arriving on untrusted ports and builds a binding table. Only ports toward the legitimate server are marked trusted.

  • D — Port security limits MAC addresses, not DHCP messages.
  • B — DAI validates ARP using the snooping binding table; it does not stop DHCP offers.
  • C — BPDU Guard protects against rogue switches sending BPDUs.

Concept being tested

Threats and mitigation, device access control, password policy, IPsec/VPN concepts, ACLs, Layer 2 security (DHCP snooping, DAI, port security), AAA, wireless security and WPA2/WPA3. — 15% of the exam. Study guide for Security Fundamentals.

Related questions

Practice this topic

Blueprint-mapped questions with full rationales for every choice.

Start practice

Primary references

  1. CCNA Exam v1.1 (200-301) Exam Topics — Cisco Systems · primary · retrieved 2026-09-21, verified 2026-09-21
Draft — pending editorial reviewHow we verify facts