Courseiva
Infrastructure →mediumMultiple Choice

CCNP Infrastructure Practice Question

A network engineer is deploying a new branch office that must use dynamic ARP inspection (DAI) on its access switches. The engineer wants to minimize manual configuration while ensuring that only valid IP-to-MAC bindings are permitted. Which feature should be enabled on the switches to provide the required binding information to DAI?

⚠ Common exam trap

The trap here is assuming that IP Source Guard or port security can supply the binding table that DAI needs, when in fact DHCP snooping is the feature that builds and maintains those bindings.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

DHCP snooping

Dynamic ARP inspection relies on the DHCP snooping binding table to validate ARP packets on untrusted ports. Without a source of legitimate IP-to-MAC bindings, DAI cannot distinguish spoofed ARP replies from valid ones. Enabling DHCP snooping on the access switches automatically populates that table as clients obtain leases, which satisfies the requirement to minimize manual configuration while protecting the branch office from ARP poisoning.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    802.1X

    Why it's wrong here

    802.1X provides port-based network access control by authenticating supplicants before granting access. It does not generate IP-to-MAC bindings for ARP inspection. Although 802.1X can be part of a secure access design, it does not fulfill the specific need to supply DAI with valid bindings, so it would not meet the stated requirement.

  • ✗

    IP Source Guard

    Why it's wrong here

    IP Source Guard filters IP traffic based on the DHCP snooping binding table, but it does not supply binding information to DAI. In this scenario, DAI needs a source of valid IP-to-MAC mappings; IP Source Guard is a consumer of that data, not a provider. Enabling it alone would not satisfy the requirement to feed DAI with trusted bindings.

  • ✓

    DHCP snooping

    Why this is correct

    DHCP snooping builds a binding table of IP address, MAC address, VLAN, and interface by snooping DHCP conversations. Dynamic ARP inspection uses this table to validate ARP packets on untrusted ports. Enabling DHCP snooping on the access switches provides the required bindings automatically, minimizing manual configuration while allowing DAI to block ARP spoofing.

  • ✗

    Port security

    Why it's wrong here

    Port security restricts the number of MAC addresses allowed on a switchport and can take action when a violation occurs. It does not create an IP-to-MAC binding table that DAI can reference. While it can help against MAC flooding, it does not provide the dynamic binding information that DAI requires to validate ARP packets in this branch office scenario.

Visual reference

Client DHCP Server 1 Discover (broadcast) 2 Offer (IP: 192.168.1.10) 3 Request (I accept) 4 Acknowledge (lease confirmed) DORA — the four-step DHCP lease process

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.