hardMultiple Select
CCNP Practice Question: Which three statements about dynamic ARP…
Which three statements about dynamic ARP inspection (DAI) are true? (Choose three.)
⚠ Common exam trap
The trap is thinking DAI inspects destination IPs or covers IPv6 — candidates confuse DAI with other inspection features and forget it only validates sender information in IPv4 ARP.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DAI validates ARP packets by checking the sender MAC and IP addresses against the DHCP snooping binding table.
Option A is correct because DAI works by intercepting ARP packets on untrusted ports and comparing the sender MAC and sender IP against entries in the DHCP snooping binding table (or a configured ARP ACL), dropping packets that do not match. Option B is correct because DAI is enabled per VLAN with the global configuration command 'ip arp inspection vlan <vlan-list>', allowing selective deployment on the VLANs that need protection. Option C is correct because DAI supports ARP packet rate limiting via the 'ip arp inspection limit rate <pps>' interface command, which protects the switch CPU from ARP flooding and denial-of-service attacks. Option D is not correct because DAI inspects only IPv4 ARP packets; IPv6 Neighbor Discovery is handled by IPv6 First-Hop Security features such as IPv6 snooping, not DAI. Option E is not correct because DAI validates the sender MAC and sender IP (and optionally the destination MAC against the binding table), not the destination IP in ARP requests, so it does not operate in the way described.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
DAI validates ARP packets by checking the sender MAC and IP addresses against the DHCP snooping binding table.
Why this is correct
DAI intercepts ARP packets on untrusted ports and compares each packet's sender MAC and sender IP against the DHCP snooping binding database, dropping any mismatch. This satisfies the stem's requirement for a true statement, since the binding table is the sole trust anchor DAI consults before forwarding ARP traffic.
- ✓
DAI can be configured on a per-VLAN basis using the 'ip arp inspection vlan' command.
Why this is correct
DAI is enabled per VLAN with the global `ip arp inspection vlan` command, satisfying the stem's requirement for VLAN-scoped deployment. This lets you protect selected VLANs while leaving others untrusted, since inspection is applied at VLAN granularity rather than globally across the switch.
- ✓
DAI includes rate limiting to prevent ARP flooding attacks.
Why this is correct
DAI's rate-limiting feature caps incoming ARP packets per second on untrusted interfaces, dropping excess traffic once the configured threshold is exceeded. This directly counters ARP flooding attacks, where an attacker overwhelms the switch's control plane with spoofed ARP requests, satisfying the scenario's requirement for flood mitigation.
- ✗
DAI inspects both IPv4 ARP and IPv6 Neighbor Discovery packets.
Why it's wrong here
DAI operates solely on IPv4 ARP packets; IPv6 Neighbor Discovery is handled by IPv6 First-Hop Security features such as ND inspection, not DAI. It is tempting because DAI and ND inspection share the same goal of validating address bindings, so ND inspection would be correct for an IPv6 deployment.
- ✗
DAI validates the destination IP address in ARP requests to prevent man-in-the-middle attacks.
Why it's wrong here
DAI validates the sender MAC and sender IP pairing in ARP packets against the DHCP snooping binding table; it does not inspect the destination IP field of ARP requests. It is tempting because validating bindings does prevent ARP spoofing man-in-the-middle attacks, which is DAI's actual purpose.
Visual reference
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.