350-401 Security Practice Question
A network administrator is deploying a Cisco Catalyst switch with DHCP snooping. The switch is configured with DHCP snooping globally and on VLAN 10. A DHCP server is connected to GigabitEthernet1/0/5, and client devices are connected to GigabitEthernet1/0/6 through 1/0/20. The administrator notices that DHCP offers from the server are being dropped. What is the most likely cause?
⚠ Common exam trap
The trap here is assuming that enabling DHCP snooping globally and on the VLAN is sufficient, when in fact the server-facing port must also be explicitly trusted.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The DHCP server port is not configured as trusted.
DHCP snooping treats all ports as untrusted by default and drops DHCP server messages received on untrusted ports. To allow legitimate DHCP server responses, the port connected to the DHCP server must be configured with 'ip dhcp snooping trust'. In this scenario, the server port GigabitEthernet1/0/5 is untrusted, so offers are dropped. Trusting the server port resolves the issue while maintaining protection against rogue DHCP servers on client ports.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The DHCP snooping database agent is not configured.
Why it's wrong here
The DHCP snooping database agent is used to store bindings persistently across reboots. It does not affect the forwarding of DHCP offers in real time. Without a database agent, bindings are lost on reload, but DHCP operation continues normally. The dropped offers are not caused by a missing database agent, which is an optional configuration for binding persistence.
- ✗
The client ports are configured as trusted.
Why it's wrong here
If client ports were trusted, DHCP snooping would not inspect their traffic, but that would not cause server offers to be dropped. Trust on client ports is a security risk because it allows rogue DHCP servers, but it does not explain the drop of legitimate server offers. The issue is on the server-facing port, which must be trusted to receive server messages.
- ✗
DHCP snooping is not enabled on the VLAN of the client ports.
Why it's wrong here
The scenario states DHCP snooping is enabled on VLAN 10, which is the VLAN of the client ports. If snooping were not enabled on the VLAN, DHCP would pass through without inspection, and offers would not be dropped. The symptom of dropped offers points to a trust issue, not a VLAN enablement issue. Enabling snooping on the wrong VLAN would cause other problems, but not this specific drop.
- ✓
The DHCP server port is not configured as trusted.
Why this is correct
DHCP snooping drops DHCP server messages (OFFER, ACK) received on untrusted ports. By default, all ports are untrusted. The port connected to the DHCP server must be explicitly configured with 'ip dhcp snooping trust' to allow server responses. Since the server is on GigabitEthernet1/0/5 and is not trusted, its offers are dropped, matching the symptom.
Visual reference
Go deeper
Related to this question
Learn chapter
SDN Controllers and Cisco ACI
Key term
L2 Security Features
L2 Security Features are network security mechanisms that operate at Layer 2 of the OSI model to protect local network traffic from threats like MAC spoofing, ARP attacks, and unauthorized access.
Key term
DHCP snooping
DHCP snooping is a network security feature that filters untrusted DHCP messages to prevent rogue DHCP servers from giving out false IP addresses.
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.