Courseiva

CCNA Network Services and Security Practice Question

A network administrator is configuring DHCP snooping on a Cisco Catalyst switch. The switch has a trunk port Gi1/0/24 connecting to another switch, and several access ports connecting to end-user PCs. The administrator issues the commands 'ip dhcp snooping', 'ip dhcp snooping vlan 10', and then configures interface Gi1/0/24 with 'ip dhcp snooping trust'. A PC connected to Gi1/0/5 (an untrusted port) sends a DHCPDISCOVER. What will the switch do with this DHCPDISCOVER message?

⚠ Common exam trap

The trap here is assuming that untrusted ports cannot send any DHCP messages, when in fact they can send client-originated requests but cannot receive server replies.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Forward the DHCPDISCOVER to trusted ports only, and drop any DHCPOFFER received on untrusted ports.

When DHCP snooping is enabled on a VLAN, switch ports are untrusted by default. Client DHCP messages such as DHCPDISCOVER are allowed from untrusted ports and forwarded toward trusted ports. Server messages such as DHCPOFFER, DHCPACK, and DHCPNAK are dropped if received on untrusted ports. Trusting the uplink port allows legitimate server replies to enter the switch while blocking rogue DHCP servers on access ports.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Drop the DHCPDISCOVER because only trusted ports can send DHCP messages.

    Why it's wrong here

    DHCP snooping does not block client-originated DHCP messages on untrusted ports; it allows them so that clients can obtain leases. Trusted ports are typically those facing the DHCP server or an uplink, and they are exempt from rate limiting and filtering of server messages. Dropping all DHCP messages from untrusted ports would break normal client operation.

  • ✓

    Forward the DHCPDISCOVER to trusted ports only, and drop any DHCPOFFER received on untrusted ports.

    Why this is correct

    With DHCP snooping enabled on VLAN 10, the switch treats Gi1/0/5 as untrusted by default. It allows client-originated DHCPDISCOVER messages to be forwarded toward trusted ports (such as the uplink to the DHCP server) but blocks DHCP server replies like DHCPOFFER on untrusted ports. This prevents rogue DHCP servers on access ports while permitting legitimate client requests.

  • ✗

    Forward the DHCPDISCOVER to all ports in VLAN 10, including untrusted access ports.

    Why it's wrong here

    DHCP snooping filters DHCP server messages on untrusted ports, but it does not flood client requests to all ports in the VLAN. The switch forwards the DHCPDISCOVER based on normal MAC address learning and the trusted port configuration, not by flooding to every access port. Flooding to untrusted ports could allow a rogue server to respond.

  • ✗

    Convert the untrusted port to a trusted port automatically after receiving the first DHCPDISCOVER.

    Why it's wrong here

    DHCP snooping does not automatically change port trust state. Trust must be configured manually on ports connected to legitimate DHCP servers or uplinks. Automatic trust would defeat the purpose of the feature, which is to prevent unauthorized DHCP servers from offering addresses to clients. The untrusted port remains untrusted until explicitly configured otherwise.

Visual reference

Client DHCP Server 1 Discover (broadcast) 2 Offer (IP: 192.168.1.10) 3 Request (I accept) 4 Acknowledge (lease confirmed) DORA — the four-step DHCP lease process

About these practice questions

This 200-301 question is part of Courseiva's 1,450-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.