CCNP IP Source Guard (IPSG) Practice Question
Exhibit
Refer to the exhibit. interface GigabitEthernet0/1 ip access-group ACL-IN in ip verify source port-security ! ip access-list extended ACL-IN permit tcp 10.0.0.0 0.255.255.255 any eq 80 permit tcp 10.0.0.0 0.255.255.255 any eq 443 deny ip any any
Refer to the exhibit. A switch has IP Source Guard (IPSG) and port-security enabled on interface GigabitEthernet0/1. A host with IP 10.1.1.1 and MAC 00:1A:2B:3C:4D:5E is connected and tries to access a web server at 192.168.1.100. What will happen?
⚠ Common exam trap
The trap is that many candidates assume port-security alone satisfies IPSG requirements, but IPSG needs a separate IP-MAC binding from DHCP snooping or static configuration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The traffic is blocked because IP Source Guard requires a static binding for the host.
IP Source Guard (IPSG) validates the source IP address of traffic using DHCP snooping bindings or static IP-source bindings. In this scenario, no DHCP snooping binding exists (host is not using DHCP) and no static binding has been configured, so IPSG will drop the traffic from the host. Port-security ensures the source MAC is valid, but does not provide the IP-MAC binding required by IPSG. Therefore, the traffic is blocked.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The traffic is blocked because the host is not using DHCP, so IPSG drops all non-DHCP traffic.
Why it's wrong here
Incorrect. IPSG does not drop all non-DHCP traffic if a static binding is configured, but in this case no such binding exists.
- ✗
The traffic is permitted only if the destination is also in the 10.0.0.0/8 range.
Why it's wrong here
Incorrect. IPSG does not check the destination IP; it checks the source IP against bindings. Destination subnet is irrelevant.
- ✓
The traffic is blocked because IP Source Guard requires a static binding for the host.
Why this is correct
Correct. Without DHCP or a static IP-source binding, IPSG blocks the traffic.
- ✗
The traffic is permitted because the host's IP is within the allowed subnet and the MAC is valid according to port-security.
Why it's wrong here
Incorrect. Port-security does not create an IPSG binding; without a valid IP-MAC binding, IPSG will drop the traffic even if the MAC is allowed.
Visual reference
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.