Courseiva
mediumMultiple Choice

350-401 Practice Question: Consider the following DHCP snooping…

Consider the following DHCP snooping configuration on a Cisco IOS-XE switch: ```

ip dhcp snooping
ip dhcp snooping vlan 10
interface GigabitEthernet0/1
 ip dhcp snooping trust

!

interface GigabitEthernet0/2
 ip dhcp snooping limit rate 10

``` Which statement is true?

⚠ Common exam trap

Cisco often tests the misconception that 'ip dhcp snooping limit rate' implies trust or that rate limiting applies globally, when in fact it is an interface-level feature that only applies to untrusted interfaces.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Gi0/1 is trusted for DHCP snooping, and Gi0/2 will drop DHCP packets exceeding 10 per second.

The 'ip dhcp snooping trust' command on Gi0/1 explicitly marks that interface as trusted, allowing all DHCP messages through without inspection. On Gi0/2, the 'ip dhcp snooping limit rate 10' command applies a rate limit of 10 packets per second to DHCP traffic; any DHCP packets exceeding this rate are dropped, which is a standard DHCP snooping rate-limiting behavior.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Gi0/1 is trusted for DHCP snooping, and Gi0/2 will drop DHCP packets exceeding 10 per second.

    Why this is correct

    Correct. In DHCP snooping, a trusted port is explicitly configured to receive DHCP server traffic, so Gi0/1 bypasses all DHCP snooping validation and forwards DHCP packets normally. Gi0/2 is not configured as trusted, making it an untrusted port; the 'ip dhcp snooping limit rate 10' command applies rate limiting to that interface, so any DHCP packets exceeding 10 per second on Gi0/2 will be dropped.

  • ✗

    Gi0/2 is trusted and will forward all DHCP packets without rate limiting.

    Why it's wrong here

    Incorrect. Trusted ports must be explicitly configured with the 'ip dhcp snooping trust' interface command. Since Gi0/2 has no such configuration, it remains an untrusted port and is subject to DHCP snooping validation and the configured rate limit of 10 packets per second. Therefore, Gi0/2 will not forward all DHCP packets without rate limiting; it will drop excess traffic and also inspect incoming DHCP messages for spoofed server replies and invalid bindings.

  • ✗

    The switch will only snoop DHCP on VLAN 10, but rate limiting applies to all VLANs.

    Why it's wrong here

    Incorrect. DHCP snooping is enabled per VLAN using 'ip dhcp snooping vlan 10', which restricts the snooping database and validation to that VLAN, but the 'ip dhcp snooping limit rate' command is applied per interface and does not have a VLAN qualifier. The rate limit on Gi0/2 is an interface-level policing policy that counts all DHCP packets received on that interface, regardless of which VLAN they belong to, so it applies to any VLAN traffic arriving on Gi0/2.

  • ✗

    Gi0/1 will rate-limit DHCP packets to 10 per second.

    Why it's wrong here

    Incorrect. Gi0/1 is the trusted port in this scenario, and trusted ports do not have DHCP rate limiting applied; rate limiting is designed only for untrusted ports to mitigate DHCP starvation attacks. Additionally, the 'ip dhcp snooping limit rate 10' directive is configured on Gi0/2, not on Gi0/1, so Gi0/1 will neither rate-limit nor drop DHCP packets based on a rate threshold. Trusted ports are expected to carry legitimate DHCP server traffic and must not be rate-limited.

Visual reference

Client DHCP Server 1 Discover (broadcast) 2 Offer (IP: 192.168.1.10) 3 Request (I accept) 4 Acknowledge (lease confirmed) DORA — the four-step DHCP lease process

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.