Courseiva

CCNA Network Services and Security Practice Question

Which three features are used to mitigate Layer 2 security threats on a Cisco switch? (Choose three.)

⚠ Common exam trap

Cisco often tests the distinction between features that improve STP convergence (like PortFast) and features that provide security (like BPDU guard), causing candidates to mistakenly select PortFast as a security feature.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Dynamic ARP Inspection (DAI) to prevent ARP spoofing.

Dynamic ARP Inspection (DAI) is correct because it validates ARP packets against the DHCP snooping binding table, dropping ARP spoofing/poisoning attempts that enable man-in-the-middle attacks at Layer 2. DHCP snooping is correct because it builds and maintains the trusted binding database of IP-to-MAC-to-port-to-VLAN mappings that DAI relies on, and it also rate-limits and filters rogue DHCP server messages. BPDU guard is correct because it err-disables access ports that receive BPDUs, preventing an attacker from injecting a rogue switch or manipulating STP topology. PortFast is not a mitigation feature — it only speeds up STP convergence on edge ports and actually increases risk unless paired with BPDU guard. EtherChannel load balancing is a bandwidth/availability feature, not a Layer 2 threat mitigation. Using VLAN 1 as the native VLAN on trunks is a poor practice that can enable VLAN hopping, so it does not mitigate threats.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    PortFast on all access ports to prevent STP convergence delays.

    Why it's wrong here

    PortFast skips listening and learning states on access ports, which speeds host connectivity but also lets a rogue switch or hub join instantly, worsening STP attacks. It is correct on end-device ports only when paired with BPDU Guard, not as a mitigation itself.

  • ✓

    Dynamic ARP Inspection (DAI) to prevent ARP spoofing.

    Why this is correct

    Dynamic ARP Inspection intercepts ARP packets on untrusted ports and validates them against the DHCP snooping binding table, dropping forged replies. This directly neutralises ARP spoofing, the Layer 2 man-in-the-middle threat named in the stem, satisfying the mitigation requirement.

  • ✓

    DHCP snooping to build a trusted binding database.

    Why this is correct

    DHCP snooping classifies ports as trusted or untrusted and records legitimate client-to-IP bindings in a database, filtering rogue DHCP offers. That binding table also feeds DAI and IP Source Guard, mitigating the Layer 2 DHCP spoofing threat named in the stem.

  • ✓

    BPDU guard to shut down ports receiving BPDUs on access ports.

    Why this is correct

    BPDU guard errs-disables a PortFast access port the moment it receives a BPDU, blocking rogue switches from injecting superior STP topology information. This prevents spanning-tree manipulation, the Layer 2 threat the stem asks to mitigate.

  • ✗

    EtherChannel load balancing to increase bandwidth.

    Why it's wrong here

    EtherChannel load balancing distributes frames across links for bandwidth and redundancy; it provides no protection against MAC flooding, DHCP snooping or ARP spoofing. It is the right design when uplink throughput or link resilience is the requirement, not threat mitigation.

  • ✗

    VLAN 1 as the native VLAN on trunk ports for management.

    Why it's wrong here

    VLAN 1 as native on trunks is itself a Layer 2 risk, since untagged frames land there and enable VLAN hopping. Best practise is changing the native VLAN to an unused one. VLAN 1 remains acceptable only for legacy management where no trunk carries it.

Visual reference

Client DHCP Server 1 Discover (broadcast) 2 Offer (IP: 192.168.1.10) 3 Request (I accept) 4 Acknowledge (lease confirmed) DORA — the four-step DHCP lease process

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

Go deeper

Related to this question

About these practice questions

One of 1,450 original 200-301 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.