DHCP questions cover server configuration, relay agents (ip helper-address), DHCP snooping, and the four-step DORA handshake. Common exam scenarios: a host isn't getting an IP, a relay agent isn't forwarding requests, or a rogue DHCP server is handing out wrong addresses.
Start Scenario PracticeDrag and drop the steps of DHCP snooping operation on a Cisco switch into the correct order, from first to last.
Explanation: DHCP snooping begins by enabling the feature globally with 'ip dhcp snooping'. Then, the feature is enabled on specific VLANs. Trusted interfaces (typically uplinks to DHCP servers) are configured with 'ip dhcp snooping trust'. The switch then intercepts DHCP messages, building the DHCP snooping binding database from valid server responses. Finally, any DHCP server messages received on untrusted interfaces are dropped to prevent rogue server attacks.
A network engineer is troubleshooting a DHCP issue where a client is not receiving an IP address from a Cisco router configured as a DHCP server. The engineer checks the DHCP pool configuration and sees that the network command is configured with the correct subnet. The engineer also verifies that the ip dhcp excluded-address command is not blocking any addresses. However, the client's DHCP discover message is not reaching the router. What is the most likely cause?
Explanation: If the client and the router's DHCP server interface are on different VLANs (i.e., different subnets), the DHCP discover broadcast will not cross the Layer 3 boundary unless the router interface has an ip helper-address configured. The ip helper-address command enables the router to convert the broadcast DHCP discover into a unicast and forward it to the DHCP server. Without it, the client's broadcast never reaches the server, even if the DHCP pool is correctly defined.
An architect is planning a virtualized infrastructure for a branch office that will host a Cisco ISRv router and a local DHCP server. The architect wants to minimize management overhead and ensure the VMs can be easily backed up. Which hypervisor deployment model is most appropriate?
Explanation: A Type 1 hypervisor (bare-metal) runs directly on the server hardware, providing near-native performance for the Cisco ISRv router and DHCP server. Centralized management via vCenter or similar tools reduces administrative overhead and enables efficient VM backup and recovery, meeting the architect's requirements for minimal management overhead and easy backup.
A network engineer is configuring dynamic ARP inspection (DAI) on a Cisco switch to prevent ARP spoofing. The switch has DHCP snooping enabled and the DHCP server is trusted. The engineer enables DAI on VLAN 10 and configures 'ip arp inspection trust' on the port connected to the DHCP server. After enabling DAI, some legitimate ARP replies from hosts are being dropped. The engineer checks the DAI statistics and sees 'ARP ACL drops' incrementing. What is the most likely reason?
Explanation: When DAI is enabled on a VLAN, it validates ARP packets against the DHCP snooping binding database. If a host has a static IP address, its MAC-IP binding is not automatically present in the DHCP snooping database. Without a valid binding, DAI treats the ARP reply as invalid and drops it, incrementing the 'ARP ACL drops' counter. The correct solution is to either configure static DHCP snooping bindings or use ARP ACLs to permit the static hosts.
Drag and drop the steps of stateless DHCPv6 address assignment steps into the correct order, from first to last.
Explanation: Stateless DHCPv6 uses SLAAC for addressing and DHCPv6 for additional parameters. The host sends an RS, receives an RA with the O flag, then sends an Information-Request and receives a Reply with options like DNS.
+10 more scenario questions available
Practice all DHCP Troubleshooting ScenariosDHCP questions cover server configuration, relay agents (ip helper-address), DHCP snooping, and the four-step DORA handshake. Common exam scenarios: a host isn't getting an IP, a relay agent isn't forwarding requests, or a rogue DHCP server is handing out wrong addresses. These appear throughout the 350-401 and require you to apply your knowledge, not just recall facts.
Cisco doesn't publish an exact breakdown, but scenario-based questions (especially exhibit and command-output formats) make up a significant portion of the 350-401. Practicing each scenario type ensures you're ready for any format.
Yes. Courseiva provides free 350-401 scenario practice across all official exam domains. The platform includes scenario-based questions, command-output interpretation, topic-based practice, mock exams, and readiness tracking — no account required.
Launch a full DHCP Troubleshooting Scenarios session with instant scoring and detailed explanations.
Start Scenario Practice →