CCNP Security Practice Question
A Cisco Catalyst 9500 switch in a data center is configured with IP Source Guard on an access port where a server is connected. The server has a static IP address of 10.10.10.50 and MAC address 00:11:22:33:44:55. The network administrator has configured a static IP source binding using the command 'ip source binding 0011.2233.4455 vlan 10 10.10.10.50 interface GigabitEthernet1/0/1'. However, the server cannot communicate through the switch. What is the most likely cause?
⚠ Common exam trap
The trap here is assuming that static IP source bindings eliminate the need for DHCP snooping, when in fact DHCP snooping must be enabled on the VLAN for IP Source Guard to function.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
IP Source Guard requires DHCP snooping to be enabled on the VLAN even when static bindings are used.
IP Source Guard uses the DHCP snooping binding table to validate source IP and MAC addresses on a port. Static bindings can be added manually, but DHCP snooping must still be enabled on the VLAN to activate the binding table and allow IP Source Guard to filter traffic. Without DHCP snooping, the static binding is not effective, and the switch may drop legitimate traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
IP Source Guard only works on trunk ports, not access ports.
Why it's wrong here
IP Source Guard is commonly deployed on access ports to filter traffic from end devices. It can also be used on trunk ports in some designs, but there is no restriction that it only works on trunk ports. The server is connected to an access port, which is a supported configuration.
- ✓
IP Source Guard requires DHCP snooping to be enabled on the VLAN even when static bindings are used.
Why this is correct
IP Source Guard relies on the DHCP snooping binding table to validate IP-to-MAC bindings. Even with static entries, DHCP snooping must be enabled on the VLAN to maintain the binding table and allow IP Source Guard to function. Without it, the switch cannot validate traffic and may drop packets, causing the server to lose connectivity.
- ✗
The static IP source binding must be configured with the MAC address in the format xx:xx:xx:xx:xx:xx.
Why it's wrong here
Cisco IOS accepts MAC addresses in various formats, including dotted hexadecimal (0011.2233.4455) and colon-separated. The format used is valid and not the cause of the problem. The issue lies in the underlying dependency on DHCP snooping, not the MAC address notation.
- ✗
The server must use DHCP to obtain its IP address for IP Source Guard to permit traffic.
Why it's wrong here
While IP Source Guard often works with DHCP-assigned addresses, static IP source bindings are explicitly supported to allow hosts with static IPs. The server can retain its static IP, provided the binding is correctly installed and DHCP snooping is enabled. The requirement for DHCP is a misconception.
Visual reference
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.