CCNA Network Services and Security Practice Question
A switch port is configured with DHCP snooping trust on the uplink toward the legitimate DHCP server, and DHCP snooping is enabled on the user VLAN. A user connects a rogue DHCP server to an untrusted access port. Which two statements describe what DHCP snooping does in this situation? (Choose two.)
⚠ Common exam trap
The trap here is assuming DHCP snooping blocks all DHCP traffic on untrusted ports, when it actually blocks only server-originated messages and still permits client requests.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DHCP server messages received on the untrusted access port are dropped.
DHCP snooping builds a binding table from legitimate client transactions and blocks server messages on untrusted ports. Client messages on untrusted access ports are permitted and forwarded uplink, while rogue server offers on those same ports are discarded. This combination stops the rogue server without disrupting normal client DHCP behavior.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
DHCP server messages received on the untrusted access port are dropped.
Why this is correct
DHCP snooping classifies ports as trusted or untrusted. Server-originated messages such as OFFER and ACK arriving on an untrusted port are discarded, which prevents a rogue server on an access port from handing out addresses. This is the core protection the feature provides in this scenario.
- ✗
The access port is automatically converted to a trusted port after the first DHCP packet is seen.
Why it's wrong here
Trust status is administratively configured with ip dhcp snooping trust and is not changed dynamically by traffic. An access port remains untrusted until an administrator changes it. Automatic conversion would undermine the security model, so this statement does not describe DHCP snooping behavior.
- ✗
The switch disables the entire VLAN and places it in err-disabled state.
Why it's wrong here
DHCP snooping drops offending packets but does not err-disable a VLAN. Port security and similar features can err-disable ports, but DHCP snooping itself does not shut down the VLAN. The VLAN continues to operate, and legitimate clients can still obtain addresses from the trusted server.
- ✗
The rogue server's MAC address is added to the snooping binding table as a trusted entry.
Why it's wrong here
The binding table stores legitimate client bindings of IP address, MAC address, VLAN, interface, and lease time. A rogue server's frames are dropped, so no binding is created for it. Adding it as trusted would defeat the purpose of snooping and is not how the feature behaves.
- ✓
Client DHCP messages received on the untrusted access port are still forwarded toward the trusted uplink.
Why this is correct
DHCP snooping allows client-originated messages such as DISCOVER and REQUEST on untrusted ports because those are expected from end devices. They are forwarded toward trusted ports so the legitimate server can respond. Only server messages are blocked on untrusted ports, preserving normal client operation.
Visual reference
Go deeper
Related to this question
Learn chapter
Troubleshoot: Route Missing from Routing Table
Key term
VLAN
A VLAN logically segments a physical network into isolated broadcast domains without requiring separate physical switches.
Key term
DHCP snooping
DHCP snooping is a network security feature that filters untrusted DHCP messages to prevent rogue DHCP servers from giving out false IP addresses.
About these practice questions
Courseiva writes every 200-301 question from scratch — 1,450 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.