Drag and drop the Cisco IOS attack-mitigation features from the left to the network attack types they mitigate on the right. <DragDrop items={["DHCP snooping","Dynamic ARP Inspection","IP Source Guard","storm control"]} slots={[{"answer":"DHCP snooping","id":"slot1","label":"rogue server that spoofs IP configuration"},{"answer":"Dynamic ARP Inspection","id":"slot2","label":"cache poisoning"},{"answer":"storm control","id":"slot3","label":"flood attacks"},{"answer":"IP Source Guard","id":"slot4","label":"rogue clients on the network"}]} explanation={"DHCP snooping blocks untrusted DHCP server responses and builds the binding table used for client validation, so it addresses rogue DHCP servers that hand out spoofed IP configuration. Dynamic ARP Inspection checks ARP packets against trusted bindings, which prevents ARP cache-poisoning attacks. Storm control rate-limits excessive Layer 2 traffic such as broadcast, multicast, or unknown unicast bursts, which mitigates flood attacks. IP Source Guard filters traffic based on valid source IP/MAC bindings on a port, which helps stop rogue or spoofing clients from using unauthorized addresses.\n\n**Learn more:** [Cisco: Layer 2 Security Features on Catalyst Switches Configuration Example](https://www.cisco.com/c/en/us/support/docs/switches/catalyst-3750-series-switches/72846-layer2-secftrs-catl3fixed.html) · [Cisco: Troubleshoot Dynamic ARP Inspection (DAI) and IP Source Guard (IPSG)](https://www.cisco.com/c/en/us/support/docs/switches/lan-switch-software/222274-troubleshoot-dynamic-arp-inspection-dai.html)"} reuse={false} />