Q44Network Access
What is used to identify spurious DHCP servers?
← → navigate · a answer
Community votes
Discussion · 17
8
C. DHCPOFFER is the right answer because it is the message sent by both legitimate and rogue DHCP servers in reply to a DHCPDISCOVER, which lets you identify spurious DHCP servers.
By Dhendup Dukpa
D 4
Selected Answer: D
"You can detect spurious DHCP servers by sending dummy DHCPDISCOVER packets out to all of the DHCP servers so that a response is sent back to the switch."
Ref: https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst6500/ios/15-4SY/config_guide/sup6T/15_3_sy_swcg_6T/dhcp_snooping.html
Under Section: Trusted and Untrusted Sources
D is correct
3
You can detect spurious DHCP servers by sending dummy DHCPDISCOVER packets out to all of the DHCP servers so that a response is sent back to the switch.
D 3
Selected Answer: D
To identify spurious DHCP servers, you can use D. DHCPDISCOVER packets. By sending out dummy DHCPDISCOVER packets, a network device can listen for DHCPOFFER responses from DHCP servers. If a response is received from an unexpected source, it could mean the presence of a spurious or rogue DHCP server on the network12. This is part of the DHCP snooping feature that helps to ensure network security by validating DHCP messages and filtering out invalid ones from untrusted sources
https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst6500/ios/12-2SX/configuration/guide/book/snoodhcp.pdf
C 3
Selected Answer: C
For all you that said D is the answer , I have one question to you : what is the anatomy of the DHCPDiscover message? it's a broadcast layer 2 and layer 3 and nothing more in the Discover then when the DHCP server see's that he picks a IP from the pool , makes a ARP entery (MAC from Source Discovery message + IP that the DHCP server wants to Assign ) in he's table and sends the OFFER . So in the OFFER we have some relevant information not in the Discover message.
3
My logic was good but after reading more about other ppls point of view I know it's DHPCDiscover, it is a layer 2 broadcast but you are right all DHCP servers reply to our Discover and the we can see who is giving us false information . Correct is D.
D 2
Selected Answer: D
searched google I will go with D
D 2
Selected Answer: D
D. is the correct answer.
https://medium.com/@aita.official10/dhcp-snooping-binding-database-ff9464bfd539#:~:text=You%20can%20detect%20spurious%20DHCP,sent%20back%20to%20the%20switch.
C 2
Selected Answer: C
Guys, pay attention to "What is used to IDENTIFY spurious DHCP servers?" The keyword is "IDENTIFY," and the message used for identification is the DHCPOFFER.
2
That's right META AI just said so offer messages are used
D 1
Selected Answer: D
Letter D
1
i understand where you are coming from, but you cannot use a DHCPOFFER, you have to receive it, which means you have to send a DHCPDISCOVER
the spurrious server will not identify itself with a DHCPOFFER on its own, you must trigger it.
C 1
Selected Answer: C
DORA
D iscover
O ffer
R equest
A cknowledge
Before a network engineer can DISCOVER a spurious DHCP sever, the rouge DHCP sever must first OFFER it's network information that's only when the network engineer can detect any abnormalities.
C 1
Selected Answer: C
C. Even if you would use 'DHCP DISCOVER' to proactively 'hunt' rogue dhcp servers, we IDENTIFY them from the 'DHCP OFFER'.
Then again its open to interpretation. I think, since in the ccna context, dhcp snooping doesn't proactively hunt dhcp servers, just monitor if the dhcp offers are valid.
C 1
Selected Answer: C
C is correct. Unless we are actively 'hunting' (sending dhcp discovers as clients to see who responds) rogue dhcp servers, the way to identify rogue dhcp servers is through the dhcp offer/ack messages that a dhcp server would send (how dhcp snooping drops offer/acks from untrusted ports).
C 1
Selected Answer: C
The correct answer is: C. DHCPOFFER
Why the Answer is DHCPOFFER:
To identify a rogue (spurious) DHCP server, the network device (like a switch using DHCP Snooping) looks for DHCPOFFER messages coming from unauthorized ports.
Only trusted ports should send DHCPOFFER messages.
If a switch sees a DHCPOFFER on an untrusted port, it marks it as coming from a rogue DHCP server.
Why the Other Options Are Incorrect:
A. DHCPACK – This confirms assignment but the rogue server is detected first when it sends the offer.
B. DHCPREQUEST – Sent by the client, not the server.
D. DHCPDISCOVER – Sent by the client to find servers.
D 1
Selected Answer: D
DHCPDISCOVER cannot identify spurious servers :
DHCPDISCOVER is only a broadcast query from the client asking "who are you?"
It doesn't include information about whether a server is legitimate or rogue
Any DHCP server (authorized or unauthorized) will answer it
The DISCOVER message itself doesn't help identify which servers are spurious
DHCPOFFER is what identifies spurious servers with DHCP Snooping feature :
When a DHCP server responds with a DHCPOFFER, that's the point where you can actually identify it
DHCP Snooping monitors DHCPOFFER messages and verifies if they come from a trusted/authorized server