CCNA Network Services and Security Practice Question
Which three features are used to mitigate Layer 2 security threats on a Cisco switch? (Choose three.)
⚠ Common exam trap
Cisco often tests the distinction between features that improve STP convergence (like PortFast) and features that provide security (like BPDU guard), causing candidates to mistakenly select PortFast as a security feature.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Dynamic ARP Inspection (DAI) to prevent ARP spoofing.
Dynamic ARP Inspection (DAI) is correct because it validates ARP packets against the DHCP snooping binding table, dropping ARP spoofing/poisoning attempts that enable man-in-the-middle attacks at Layer 2. DHCP snooping is correct because it builds and maintains the trusted binding database of IP-to-MAC-to-port-to-VLAN mappings that DAI relies on, and it also rate-limits and filters rogue DHCP server messages. BPDU guard is correct because it err-disables access ports that receive BPDUs, preventing an attacker from injecting a rogue switch or manipulating STP topology. PortFast is not a mitigation feature — it only speeds up STP convergence on edge ports and actually increases risk unless paired with BPDU guard. EtherChannel load balancing is a bandwidth/availability feature, not a Layer 2 threat mitigation. Using VLAN 1 as the native VLAN on trunks is a poor practice that can enable VLAN hopping, so it does not mitigate threats.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
PortFast on all access ports to prevent STP convergence delays.
Why it's wrong here
PortFast skips listening and learning states on access ports, which speeds host connectivity but also lets a rogue switch or hub join instantly, worsening STP attacks. It is correct on end-device ports only when paired with BPDU Guard, not as a mitigation itself.
- ✓
Dynamic ARP Inspection (DAI) to prevent ARP spoofing.
Why this is correct
Dynamic ARP Inspection intercepts ARP packets on untrusted ports and validates them against the DHCP snooping binding table, dropping forged replies. This directly neutralises ARP spoofing, the Layer 2 man-in-the-middle threat named in the stem, satisfying the mitigation requirement.
- ✓
DHCP snooping to build a trusted binding database.
Why this is correct
DHCP snooping classifies ports as trusted or untrusted and records legitimate client-to-IP bindings in a database, filtering rogue DHCP offers. That binding table also feeds DAI and IP Source Guard, mitigating the Layer 2 DHCP spoofing threat named in the stem.
- ✓
BPDU guard to shut down ports receiving BPDUs on access ports.
Why this is correct
BPDU guard errs-disables a PortFast access port the moment it receives a BPDU, blocking rogue switches from injecting superior STP topology information. This prevents spanning-tree manipulation, the Layer 2 threat the stem asks to mitigate.
- ✗
EtherChannel load balancing to increase bandwidth.
Why it's wrong here
EtherChannel load balancing distributes frames across links for bandwidth and redundancy; it provides no protection against MAC flooding, DHCP snooping or ARP spoofing. It is the right design when uplink throughput or link resilience is the requirement, not threat mitigation.
- ✗
VLAN 1 as the native VLAN on trunk ports for management.
Why it's wrong here
VLAN 1 as native on trunks is itself a Layer 2 risk, since untagged frames land there and enable VLAN hopping. Best practise is changing the native VLAN to an unused one. VLAN 1 remains acceptable only for legacy management where no trunk carries it.
Visual reference
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
Learn chapter
Dynamic ARP and MAC Security Mitigation
Key term
DHCP server
A DHCP server is a network device or service that automatically assigns IP addresses and other network configuration parameters to devices on a network, eliminating the need for manual configuration.
Key term
Link Aggregation Control Protocol
Link Aggregation Control Protocol (LACP) is a standard protocol that automatically bundles multiple physical network links into a single logical link to increase bandwidth and provide redundancy.
About these practice questions
One of 1,450 original 200-301 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.