Courseiva
mediumMultiple Choice

350-401 Practice Question: Is configuring dynamic ARP inspection (DAI) on a…

A network engineer is configuring dynamic ARP inspection (DAI) on a Cisco switch to prevent ARP spoofing. The switch has DHCP snooping enabled and the DHCP server is trusted. The engineer enables DAI on VLAN 10 and configures 'ip arp inspection trust' on the port connected to the DHCP server. After enabling DAI, some legitimate ARP replies from hosts are being dropped. The engineer checks the DAI statistics and sees 'ARP ACL drops' incrementing. What is the most likely reason?

⚠ Common exam trap

Cisco often tests the misconception that DAI only works with DHCP-assigned addresses, but the real trap is that candidates forget static IP hosts require manual binding entries or ARP ACLs to avoid being dropped.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The hosts have static IP addresses, so their MAC-IP bindings are not in the DHCP snooping database.

When DAI is enabled on a VLAN, it validates ARP packets against the DHCP snooping binding database. If a host has a static IP address, its MAC-IP binding is not automatically present in the DHCP snooping database. Without a valid binding, DAI treats the ARP reply as invalid and drops it, incrementing the 'ARP ACL drops' counter. The correct solution is to either configure static DHCP snooping bindings or use ARP ACLs to permit the static hosts.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The hosts have static IP addresses, so their MAC-IP bindings are not in the DHCP snooping database.

    Why this is correct

    DAI validates ARP packets by looking up the source MAC and IP in the DHCP snooping binding table, which is populated only by DHCP-assigned addresses. Because these hosts use static IPs, no binding entry exists for them. Consequently, DAI will consider their ARP packets invalid and drop them unless an ARP ACL explicitly permits their IP-to-MAC mapping.

  • ✗

    The port connected to the DHCP server should be untrusted for DAI to work correctly.

    Why it's wrong here

    The DHCP server port must be configured as trusted, not untrusted, for DAI to operate correctly. DAI does not inspect ARP packets that arrive on trusted ports; an untrusted DHCP server port would cause DAI to drop the server's ARP messages, breaking DHCP and subsequent security verification.

  • ✗

    The DHCP server is in a different VLAN, and DAI cannot validate cross-VLAN ARP.

    Why it's wrong here

    DAI inspects ARP packets on a per-VLAN basis using the DHCP snooping binding table, which contains entries for multiple VLANs. The location of the DHCP server is irrelevant because its port is trusted and its ARP traffic is exempt from inspection; only the hosts' ARP messages are validated against their own VLAN's bindings.

  • ✗

    DAI is checking the destination MAC address, which does not match the expected value.

    Why it's wrong here

    DAI does not validate the destination MAC address in an Ethernet or ARP frame. Instead, it validates the sender hardware address and sender protocol address against the DHCP snooping binding table, then checks the frame's source MAC address. The destination is irrelevant to the binding check; DAI only cares who is speaking, not to whom the packet is directed.

Visual reference

Client DHCP Server 1 Discover (broadcast) 2 Offer (IP: 192.168.1.10) 3 Request (I accept) 4 Acknowledge (lease confirmed) DORA — the four-step DHCP lease process

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.