DHCP questions cover server configuration, relay agents (ip helper-address), DHCP snooping, and the four-step DORA handshake. Common exam scenarios: a host isn't getting an IP, a relay agent isn't forwarding requests, or a rogue DHCP server is handing out wrong addresses.
Start Scenario PracticeWhich security feature on a Nexus switch prevents a rogue DHCP server from assigning invalid IP addresses to clients?
Explanation: DHCP Snooping is a security feature on Nexus switches that prevents rogue DHCP servers from assigning invalid IP addresses by filtering DHCP messages. It classifies switch ports as trusted or untrusted; only trusted ports (connected to legitimate DHCP servers) can send DHCP offers, while untrusted ports can only send DHCP requests. This prevents unauthorized DHCP servers from responding to client requests. Other features like Port Security, IP Source Guard, and Dynamic ARP Inspection serve different purposes.
Which feature on a Nexus switch uses DHCP snooping binding information to filter IP traffic on a per-port basis?
Explanation: IP Source Guard uses DHCP snooping bindings to filter IP traffic, allowing only traffic from valid IP-MAC pairs.
Which TWO security features rely on the DHCP snooping binding table? (Select exactly 2)
Explanation: IP Source Guard (IPSG) uses the DHCP snooping binding table to validate the source IP address of packets received on untrusted ports. It drops any packet whose source IP does not match an entry in the binding table, preventing IP spoofing attacks. Dynamic ARP Inspection (DAI) also relies on the DHCP snooping binding table to validate ARP packets, ensuring that the sender MAC and IP addresses match a legitimate binding, thereby blocking ARP poisoning attacks.
An attacker attempts to spoof a legitimate client's IP address to intercept traffic. DHCP snooping is enabled. Which feature prevents this spoofing by validating source IP in data packets?
Explanation: IP Source Guard (IPSG) uses the DHCP snooping binding database to validate the source IP address in data packets received on untrusted ports. If a packet's source IP does not match an entry in the binding table, IPSG drops the packet, preventing IP spoofing attacks.
An organization is deploying Cisco Nexus 9000 switches with NX-OS and needs to prevent ARP spoofing attacks. The network engineer enables Dynamic ARP Inspection (DAI) on all VLANs. However, some legitimate hosts are unable to obtain IP addresses via DHCP. What is the most likely reason?
Explanation: DAI relies on the DHCP snooping binding table to validate ARP packets. Without DHCP snooping enabled, the binding table is empty, so DAI cannot determine which ARP packets are legitimate, causing it to drop all ARP packets, including DHCP discovery and request messages. This prevents hosts from obtaining IP addresses via DHCP.
+8 more scenario questions available
Practice all DHCP Troubleshooting ScenariosDHCP questions cover server configuration, relay agents (ip helper-address), DHCP snooping, and the four-step DORA handshake. Common exam scenarios: a host isn't getting an IP, a relay agent isn't forwarding requests, or a rogue DHCP server is handing out wrong addresses. These appear throughout the 350-601 and require you to apply your knowledge, not just recall facts.
Cisco doesn't publish an exact breakdown, but scenario-based questions (especially exhibit and command-output formats) make up a significant portion of the 350-601. Practicing each scenario type ensures you're ready for any format.
Yes. Courseiva provides free 350-601 scenario practice across all official exam domains. The platform includes scenario-based questions, command-output interpretation, topic-based practice, mock exams, and readiness tracking — no account required.
Launch a full DHCP Troubleshooting Scenarios session with instant scoring and detailed explanations.
Start Scenario Practice →