mediumMultiple Choice
350-401 Practice Question: Is configuring dynamic ARP inspection (DAI) on a…
A network engineer is configuring dynamic ARP inspection (DAI) on a Cisco switch to prevent ARP spoofing. The switch has DHCP snooping enabled and the DHCP server is trusted. The engineer enables DAI on VLAN 10 and configures 'ip arp inspection trust' on the port connected to the DHCP server. After enabling DAI, some legitimate ARP replies from hosts are being dropped. The engineer checks the DAI statistics and sees 'ARP ACL drops' incrementing. What is the most likely reason?
⚠ Common exam trap
Cisco often tests the misconception that DAI only works with DHCP-assigned addresses, but the real trap is that candidates forget static IP hosts require manual binding entries or ARP ACLs to avoid being dropped.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The hosts have static IP addresses, so their MAC-IP bindings are not in the DHCP snooping database.
When DAI is enabled on a VLAN, it validates ARP packets against the DHCP snooping binding database. If a host has a static IP address, its MAC-IP binding is not automatically present in the DHCP snooping database. Without a valid binding, DAI treats the ARP reply as invalid and drops it, incrementing the 'ARP ACL drops' counter. The correct solution is to either configure static DHCP snooping bindings or use ARP ACLs to permit the static hosts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The hosts have static IP addresses, so their MAC-IP bindings are not in the DHCP snooping database.
Why this is correct
DAI validates ARP packets by looking up the source MAC and IP in the DHCP snooping binding table, which is populated only by DHCP-assigned addresses. Because these hosts use static IPs, no binding entry exists for them. Consequently, DAI will consider their ARP packets invalid and drop them unless an ARP ACL explicitly permits their IP-to-MAC mapping.
- ✗
The port connected to the DHCP server should be untrusted for DAI to work correctly.
Why it's wrong here
The DHCP server port must be configured as trusted, not untrusted, for DAI to operate correctly. DAI does not inspect ARP packets that arrive on trusted ports; an untrusted DHCP server port would cause DAI to drop the server's ARP messages, breaking DHCP and subsequent security verification.
- ✗
The DHCP server is in a different VLAN, and DAI cannot validate cross-VLAN ARP.
Why it's wrong here
DAI inspects ARP packets on a per-VLAN basis using the DHCP snooping binding table, which contains entries for multiple VLANs. The location of the DHCP server is irrelevant because its port is trusted and its ARP traffic is exempt from inspection; only the hosts' ARP messages are validated against their own VLAN's bindings.
- ✗
DAI is checking the destination MAC address, which does not match the expected value.
Why it's wrong here
DAI does not validate the destination MAC address in an Ethernet or ARP frame. Instead, it validates the sender hardware address and sender protocol address against the DHCP snooping binding table, then checks the frame's source MAC address. The destination is irrelevant to the binding check; DAI only cares who is speaking, not to whom the packet is directed.
Visual reference
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
Learn chapter
ACLs and Infrastructure Security Features
Key term
DHCP snooping
DHCP snooping is a network security feature that filters untrusted DHCP messages to prevent rogue DHCP servers from giving out false IP addresses.
Key term
L2 Security Features
L2 Security Features are network security mechanisms that operate at Layer 2 of the OSI model to protect local network traffic from threats like MAC spoofing, ARP attacks, and unauthorized access.
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.