Drag and drop the attack-mitigation techniques on the left to the attack types they mitigate on the right. <DragDrop items={["Configure the 802.1x authentication protocol","Configure the DHCP snooping feature","Configure the native VLAN with a nondefault VLAN","Disable Dynamic Trunking Protocol – switch-spoofing VLAN-hopping attack"]} slots={[{"answer":"Configure the native VLAN with a nondefault VLAN","id":"slot1","label":"802.1q double-tagging VLAN-hopping attack"},{"answer":"Configure the 802.1x authentication protocol","id":"slot2","label":"MAC flooding attack"},{"answer":"Configure the DHCP snooping feature","id":"slot3","label":"man-in-the-middle spoofing attack"},{"answer":"Disable Dynamic Trunking Protocol – switch-spoofing VLAN-hopping attack","id":"slot4","label":"switch-spoofing VLAN-hopping attack"}]} explanation={"Double-tagging VLAN hopping exploits the native VLAN on an 802.1Q trunk, so moving the native VLAN away from the default VLAN mitigates that attack. Switch-spoofing VLAN hopping depends on trunk negotiation, so disabling DTP prevents an attacker from forming an unauthorized trunk. DHCP snooping helps prevent spoofing-based man-in-the-middle behavior by building trusted IP-to-MAC bindings and blocking rogue DHCP activity that supports impersonation attacks. 802.1X requires endpoint authentication before a port is usable, reducing the ability of unauthorized devices to connect and perform attacks such as MAC flooding.\n\n**Learn more:** [VLAN Configuration Guide - Configure VLAN Trunking](https://www.cisco.com/c/en/us/td/docs/switches/lan/c9000/lyr2-fwd/vlan/vlan-configuration-guide/configure-vlan-trunks.html) · [Security Configuration, Cisco Catalyst PON Series Switches - Preventing ARP Spoofing and Flood Attack](https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst_pon/software/configuration_guide/sec/b-gpon-config-security/preventing_arf_spoofing_and_flood_attack.html)"} reuse={false} />