Courseiva
Security →hardMultiple Choice

350-401 Security Practice Question

A Cisco Catalyst 9500 switch in a data center is configured with IP Source Guard on an access port where a server is connected. The server has a static IP address of 10.10.10.50 and MAC address 00:11:22:33:44:55. The network administrator has configured a static IP source binding using the command 'ip source binding 0011.2233.4455 vlan 10 10.10.10.50 interface GigabitEthernet1/0/1'. However, the server cannot communicate through the switch. What is the most likely cause?

⚠ Common exam trap

The trap here is assuming that static IP source bindings eliminate the need for DHCP snooping, when in fact DHCP snooping must be enabled on the VLAN for IP Source Guard to function.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

IP Source Guard requires DHCP snooping to be enabled on the VLAN even when static bindings are used.

IP Source Guard uses the DHCP snooping binding table to validate source IP and MAC addresses on a port. Static bindings can be added manually, but DHCP snooping must still be enabled on the VLAN to activate the binding table and allow IP Source Guard to filter traffic. Without DHCP snooping, the static binding is not effective, and the switch may drop legitimate traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    IP Source Guard only works on trunk ports, not access ports.

    Why it's wrong here

    IP Source Guard is commonly deployed on access ports to filter traffic from end devices. It can also be used on trunk ports in some designs, but there is no restriction that it only works on trunk ports. The server is connected to an access port, which is a supported configuration.

  • ✓

    IP Source Guard requires DHCP snooping to be enabled on the VLAN even when static bindings are used.

    Why this is correct

    IP Source Guard relies on the DHCP snooping binding table to validate IP-to-MAC bindings. Even with static entries, DHCP snooping must be enabled on the VLAN to maintain the binding table and allow IP Source Guard to function. Without it, the switch cannot validate traffic and may drop packets, causing the server to lose connectivity.

  • ✗

    The static IP source binding must be configured with the MAC address in the format xx:xx:xx:xx:xx:xx.

    Why it's wrong here

    Cisco IOS accepts MAC addresses in various formats, including dotted hexadecimal (0011.2233.4455) and colon-separated. The format used is valid and not the cause of the problem. The issue lies in the underlying dependency on DHCP snooping, not the MAC address notation.

  • ✗

    The server must use DHCP to obtain its IP address for IP Source Guard to permit traffic.

    Why it's wrong here

    While IP Source Guard often works with DHCP-assigned addresses, static IP source bindings are explicitly supported to allow hosts with static IPs. The server can retain its static IP, provided the binding is correctly installed and DHCP snooping is enabled. The requirement for DHCP is a misconception.

Visual reference

Client DHCP Server 1 Discover (broadcast) 2 Offer (IP: 192.168.1.10) 3 Request (I accept) 4 Acknowledge (lease confirmed) DORA — the four-step DHCP lease process

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

Go deeper

Related to this question

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.