Courseiva
SecurityhardMultiple ChoiceObjective-mapped

350-601 Security Practice Question

An organization is deploying Cisco Nexus 9000 switches with NX-OS and needs to prevent ARP spoofing attacks. The network engineer enables Dynamic ARP Inspection (DAI) on all VLANs. However, some legitimate hosts are unable to obtain IP addresses via DHCP. What is the most likely reason?

⚠ Common exam trap

Cisco often tests the dependency of DAI on DHCP snooping, and the trap here is that candidates assume DAI can function independently without understanding that it requires the DHCP snooping binding table for validation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

DHCP snooping is not enabled, so DAI lacks the DHCP snooping binding table.

DAI relies on the DHCP snooping binding table to validate ARP packets. Without DHCP snooping enabled, the binding table is empty, so DAI cannot determine which ARP packets are legitimate, causing it to drop all ARP packets, including DHCP discovery and request messages. This prevents hosts from obtaining IP addresses via DHCP.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The ARP rate limit on the port is too low, causing all ARP requests to be dropped.

    Why it's wrong here

    Rate limiting drops excessive ARPs but does not block all.

  • IP Source Guard is enabled and is blocking ARP packets.

    Why it's wrong here

    IP Source Guard blocks IP traffic, not ARP, and is separate from DAI.

  • DHCP snooping is not enabled, so DAI lacks the DHCP snooping binding table.

    Why this is correct

    DAI validates ARP against DHCP snooping database; without it, DAI drops all ARP on untrusted ports.

  • An ARP ACL is not configured to allow static IP bindings.

    Why it's wrong here

    ARP ACLs are not required for DAI to work with DHCP.

Visual reference

Client DHCP Server 1 Discover (broadcast) 2 Offer (IP: 192.168.1.10) 3 Request (I accept) 4 Acknowledge (lease confirmed) DORA — the four-step DHCP lease process

About these practice questions

This 350-601 question is part of Courseiva's 984-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-601 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-601 exam.