Courseiva

CCNA Network Services and Security Practice Question

A switch port is configured with DHCP snooping trust on the uplink toward the legitimate DHCP server, and DHCP snooping is enabled on the user VLAN. A user connects a rogue DHCP server to an untrusted access port. Which two statements describe what DHCP snooping does in this situation? (Choose two.)

⚠ Common exam trap

The trap here is assuming DHCP snooping blocks all DHCP traffic on untrusted ports, when it actually blocks only server-originated messages and still permits client requests.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

DHCP server messages received on the untrusted access port are dropped.

DHCP snooping builds a binding table from legitimate client transactions and blocks server messages on untrusted ports. Client messages on untrusted access ports are permitted and forwarded uplink, while rogue server offers on those same ports are discarded. This combination stops the rogue server without disrupting normal client DHCP behavior.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    DHCP server messages received on the untrusted access port are dropped.

    Why this is correct

    DHCP snooping classifies ports as trusted or untrusted. Server-originated messages such as OFFER and ACK arriving on an untrusted port are discarded, which prevents a rogue server on an access port from handing out addresses. This is the core protection the feature provides in this scenario.

  • ✗

    The access port is automatically converted to a trusted port after the first DHCP packet is seen.

    Why it's wrong here

    Trust status is administratively configured with ip dhcp snooping trust and is not changed dynamically by traffic. An access port remains untrusted until an administrator changes it. Automatic conversion would undermine the security model, so this statement does not describe DHCP snooping behavior.

  • ✗

    The switch disables the entire VLAN and places it in err-disabled state.

    Why it's wrong here

    DHCP snooping drops offending packets but does not err-disable a VLAN. Port security and similar features can err-disable ports, but DHCP snooping itself does not shut down the VLAN. The VLAN continues to operate, and legitimate clients can still obtain addresses from the trusted server.

  • ✗

    The rogue server's MAC address is added to the snooping binding table as a trusted entry.

    Why it's wrong here

    The binding table stores legitimate client bindings of IP address, MAC address, VLAN, interface, and lease time. A rogue server's frames are dropped, so no binding is created for it. Adding it as trusted would defeat the purpose of snooping and is not how the feature behaves.

  • ✓

    Client DHCP messages received on the untrusted access port are still forwarded toward the trusted uplink.

    Why this is correct

    DHCP snooping allows client-originated messages such as DISCOVER and REQUEST on untrusted ports because those are expected from end devices. They are forwarded toward trusted ports so the legitimate server can respond. Only server messages are blocked on untrusted ports, preserving normal client operation.

Visual reference

Client DHCP Server 1 Discover (broadcast) 2 Offer (IP: 192.168.1.10) 3 Request (I accept) 4 Acknowledge (lease confirmed) DORA — the four-step DHCP lease process

About these practice questions

Courseiva writes every 200-301 question from scratch — 1,450 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.