Drag steps to the numbered slots on the right, or tap a step then tap a slot.
350-401 Practice Question: Drag and drop the steps of Cisco DHCP snooping…
Drag and drop the steps of Cisco DHCP snooping binding table population into the correct order, from first to last.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
Switch receives DHCPACK from trusted server port
DHCP snooping first validates DHCP server messages on trusted ports, then creates a binding entry from the DHCPACK, stores the entry with MAC/IP/port/VLAN, updates the table on lease renewal, and finally removes the entry on lease expiry or DHCPRELEASE.
Visual reference
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
Learn chapter
IP Services: DHCP, NAT, and DNS
Key term
DHCP snooping
DHCP snooping is a network security feature that filters untrusted DHCP messages to prevent rogue DHCP servers from giving out false IP addresses.
Key term
L2 Security Features
L2 Security Features are network security mechanisms that operate at Layer 2 of the OSI model to protect local network traffic from threats like MAC spoofing, ARP attacks, and unauthorized access.
About these practice questions
One of 1,175 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on 350-401
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Drag and drop the steps of Cisco DHCP snooping binding table population into the correct order, from first to last.
medium- ✓ A.Enable DHCP snooping globally on the switch
- ✓ B.Enable DHCP snooping on specific VLANs
- ✓ C.Configure trusted ports for DHCP server connections
- ✓ D.Switch intercepts DHCPACK from server
- ✓ E.Populate binding table with MAC, IP, VLAN, port, lease
Why A: DHCP snooping builds the binding table by first enabling snooping globally, then on specific VLANs, and designating trusted ports. The switch intercepts DHCP messages, extracts client info from ACK packets, and populates the binding table with the lease information.
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.