ETExamTower
Q72Security Fundamentals

Drag and drop the Cisco IOS attack-mitigation features from the left to the network attack types they mitigate on the right. <DragDrop items={["DHCP snooping","Dynamic ARP Inspection","IP Source Guard","storm control"]} slots={[{"answer":"DHCP snooping","id":"slot1","label":"rogue server that spoofs IP configuration"},{"answer":"Dynamic ARP Inspection","id":"slot2","label":"cache poisoning"},{"answer":"storm control","id":"slot3","label":"flood attacks"},{"answer":"IP Source Guard","id":"slot4","label":"rogue clients on the network"}]} explanation={"DHCP snooping blocks untrusted DHCP server responses and builds the binding table used for client validation, so it addresses rogue DHCP servers that hand out spoofed IP configuration. Dynamic ARP Inspection checks ARP packets against trusted bindings, which prevents ARP cache-poisoning attacks. Storm control rate-limits excessive Layer 2 traffic such as broadcast, multicast, or unknown unicast bursts, which mitigates flood attacks. IP Source Guard filters traffic based on valid source IP/MAC bindings on a port, which helps stop rogue or spoofing clients from using unauthorized addresses.\n\n**Learn more:** [Cisco: Layer 2 Security Features on Catalyst Switches Configuration Example](https://www.cisco.com/c/en/us/support/docs/switches/catalyst-3750-series-switches/72846-layer2-secftrs-catl3fixed.html) · [Cisco: Troubleshoot Dynamic ARP Inspection (DAI) and IP Source Guard (IPSG)](https://www.cisco.com/c/en/us/support/docs/switches/lan-switch-software/222274-troubleshoot-dynamic-arp-inspection-dai.html)"} reuse={false} />

← → navigate · a answer
Discussion · 13
67
Correct me if I'm wrong, but this answer doesn't seem right to me at all. Shouldn't it be: DHCP Snooping - Rogue server, Dynamic ARP Inspection - Cache poisoning, IP Source Guard - rogue clients, storm control - flood attacks
32
I agree with Anon DHCP Snooping - Rogue server that spoofs ip config (rogue DHCP server) Dynamic ARP Inspection - Cache poisoning (ARP cache poisoning) storm control - flood attacks IP Source Guard - rogue clients (IP source guard is configured separated but uses the dhcp snooping bindings table to detect a malicious IP/MAC combo) https://www.cisco.com/en/US/docs/switches/lan/catalyst3850/software/release/3.2_0_se/multibook/configuration_guide/b_consolidated_config_guide_3850_chapter_0110110.html#d351221e533a1635
6
DHCP snooping Dynamic Arp inspection Storm control source guard
5
Answer should be, see use case and explanation of what each does below: IP source guard Dynamic Arp inspection Storm control DHCP snooping
4
Typical Cisco question, I asked ChatGPT and this was the answer: DHCP Snooping - Rogue clients on the network Dynamic ARP Inspection - Rogue server that spoofs IP config IP Source Guard - Cache poisoning Storm Control - Flood attacks
3
a rogue DHCP server is one that is not allowed to provide IP addresses to devices on your network. >>> prevented by DHCP snooping A rogue client is an unauthorized device that has been found communicating and accessing an authorized network. >>> prevented by IP source guard
3
Agree with Anon1216, the given answer is not correct. DHCP snooping: a security technology on a Layer 2 network switch that can prevent unauthorized DHCP servers from accessing your network. It is a protection from untrusted hosts that want to become DHCP servers. -- rogue server that spoofs IP configuration Dynamic ARP Inspection (DAI): helps prevent ARP cache poisoning attacks by validating ARP packets and ensuring they come from legitimate sources. (man-in-the-middle attack) -- cache poisoning IP source guard: only allows hosts whose IP address was assigned by a dhcp server(valid source), it relies on the information from the DHCP snooping database to do its work. block all other traffic. -- rogue clients on the network Storm control: too much broadcast storm makes the netwrok suffer badly, Storm control lets the switch monitor traffic levels and drop broadcast, multicast, and unknown unicast packets (when storm control level—is exceeded). -- flood attacks
2
Cisco IOS Feature Correct Attack Type DHCP Snooping Rogue server that spoofs IP configuration Dynamic ARP Inspection Cache poisoning IP Source Guard Rogue clients Storm Control Flood attacks
1
Dynamic ARP Inspection (DAI) is a security feature that validates Address Resolution Protocol (ARP) packets in a network. DAI allows a network administrator to intercept, log, and discard ARP packets with invalid MAC address to IP address bindings https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst4500/12-2/25ew/configuration/guide/conf/dynarp.html#96862
1
Storm control stops traffic on a LAN from being disrupted by a broadcast, multicast, or unicast storm on a port. Storm control is applicable for physical interfaces and is used to restrict unicast, broadcast and multicast ingress traffic on the Layer2 interfaces. https://www.cisco.com/c/dam/en/us/td/docs/ios-xml/ios/sec_data_acl/configuration/xe-3s/asr903/sec-storm-control-xe-3s-asr903-book.html#:~:text=Storm control prevents traffic on,traffic on the Layer2 interfaces.
1
The DHCP snooping feature decides whether traffic sources are trusted or untrusted. An untrusted source may start traffic attacks or other hostile actions. To stop such attacks, the DHCP snooping feature filters messages and rate-limits traffic from untrusted sources. https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst6500/ios/12-2SXF/native/configuration/guide/swcg/snoodhcp.pdf
1
I think you are right. People are getting stuck on the "Rogue Server" and "spoofing IP configuration". It's extremely vague. Is it spoofing its own IP configuration (IP Source Guard) or is it a DHCP server sending out spoofed DHCP packets (DHCP Snooping)? Spoofing IP Configuration would be a very odd way of saying sending out fake DHCP. So I think it would be IP source guard. Another terribly worded Cisco question.
1
DRAG DROP - Drag and drop the Cisco IOS attack mitigation features from the left onto the types of network attack they mitigate on the right. Select and Place: