Courseiva
Security →mediumMultiple Choice

350-401 Security Practice Question

A network administrator is deploying a Cisco Catalyst switch with DHCP snooping. The switch is configured with DHCP snooping globally and on VLAN 10. A DHCP server is connected to GigabitEthernet1/0/5, and client devices are connected to GigabitEthernet1/0/6 through 1/0/20. The administrator notices that DHCP offers from the server are being dropped. What is the most likely cause?

⚠ Common exam trap

The trap here is assuming that enabling DHCP snooping globally and on the VLAN is sufficient, when in fact the server-facing port must also be explicitly trusted.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The DHCP server port is not configured as trusted.

DHCP snooping treats all ports as untrusted by default and drops DHCP server messages received on untrusted ports. To allow legitimate DHCP server responses, the port connected to the DHCP server must be configured with 'ip dhcp snooping trust'. In this scenario, the server port GigabitEthernet1/0/5 is untrusted, so offers are dropped. Trusting the server port resolves the issue while maintaining protection against rogue DHCP servers on client ports.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The DHCP snooping database agent is not configured.

    Why it's wrong here

    The DHCP snooping database agent is used to store bindings persistently across reboots. It does not affect the forwarding of DHCP offers in real time. Without a database agent, bindings are lost on reload, but DHCP operation continues normally. The dropped offers are not caused by a missing database agent, which is an optional configuration for binding persistence.

  • ✗

    The client ports are configured as trusted.

    Why it's wrong here

    If client ports were trusted, DHCP snooping would not inspect their traffic, but that would not cause server offers to be dropped. Trust on client ports is a security risk because it allows rogue DHCP servers, but it does not explain the drop of legitimate server offers. The issue is on the server-facing port, which must be trusted to receive server messages.

  • ✗

    DHCP snooping is not enabled on the VLAN of the client ports.

    Why it's wrong here

    The scenario states DHCP snooping is enabled on VLAN 10, which is the VLAN of the client ports. If snooping were not enabled on the VLAN, DHCP would pass through without inspection, and offers would not be dropped. The symptom of dropped offers points to a trust issue, not a VLAN enablement issue. Enabling snooping on the wrong VLAN would cause other problems, but not this specific drop.

  • ✓

    The DHCP server port is not configured as trusted.

    Why this is correct

    DHCP snooping drops DHCP server messages (OFFER, ACK) received on untrusted ports. By default, all ports are untrusted. The port connected to the DHCP server must be explicitly configured with 'ip dhcp snooping trust' to allow server responses. Since the server is on GigabitEthernet1/0/5 and is not trusted, its offers are dropped, matching the symptom.

Visual reference

Client DHCP Server 1 Discover (broadcast) 2 Offer (IP: 192.168.1.10) 3 Request (I accept) 4 Acknowledge (lease confirmed) DORA — the four-step DHCP lease process

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.