Courseiva
Security →hardMultiple Choice

CCNP IP Source Guard (IPSG) Practice Question

Exhibit

Refer to the exhibit.

interface GigabitEthernet0/1
 ip access-group ACL-IN in
 ip verify source port-security
!
ip access-list extended ACL-IN
 permit tcp 10.0.0.0 0.255.255.255 any eq 80
 permit tcp 10.0.0.0 0.255.255.255 any eq 443
 deny ip any any

Refer to the exhibit. A switch has IP Source Guard (IPSG) and port-security enabled on interface GigabitEthernet0/1. A host with IP 10.1.1.1 and MAC 00:1A:2B:3C:4D:5E is connected and tries to access a web server at 192.168.1.100. What will happen?

⚠ Common exam trap

The trap is that many candidates assume port-security alone satisfies IPSG requirements, but IPSG needs a separate IP-MAC binding from DHCP snooping or static configuration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The traffic is blocked because IP Source Guard requires a static binding for the host.

IP Source Guard (IPSG) validates the source IP address of traffic using DHCP snooping bindings or static IP-source bindings. In this scenario, no DHCP snooping binding exists (host is not using DHCP) and no static binding has been configured, so IPSG will drop the traffic from the host. Port-security ensures the source MAC is valid, but does not provide the IP-MAC binding required by IPSG. Therefore, the traffic is blocked.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The traffic is blocked because the host is not using DHCP, so IPSG drops all non-DHCP traffic.

    Why it's wrong here

    Incorrect. IPSG does not drop all non-DHCP traffic if a static binding is configured, but in this case no such binding exists.

  • ✗

    The traffic is permitted only if the destination is also in the 10.0.0.0/8 range.

    Why it's wrong here

    Incorrect. IPSG does not check the destination IP; it checks the source IP against bindings. Destination subnet is irrelevant.

  • ✓

    The traffic is blocked because IP Source Guard requires a static binding for the host.

    Why this is correct

    Correct. Without DHCP or a static IP-source binding, IPSG blocks the traffic.

  • ✗

    The traffic is permitted because the host's IP is within the allowed subnet and the MAC is valid according to port-security.

    Why it's wrong here

    Incorrect. Port-security does not create an IPSG binding; without a valid IP-MAC binding, IPSG will drop the traffic even if the MAC is allowed.

Visual reference

Client DHCP Server 1 Discover (broadcast) 2 Offer (IP: 192.168.1.10) 3 Request (I accept) 4 Acknowledge (lease confirmed) DORA — the four-step DHCP lease process

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.