hardMultiple Select
350-401 Practice Question: Which two statements about IP Source Guard are…
Which two statements about IP Source Guard are true? (Choose two.)
⚠ Common exam trap
The trap is assuming IPSG only works with DHCP and cannot handle static IPs, or confusing it with DAI/port security; candidates may also think IPSG filters destination MAC, which is wrong.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
IP Source Guard uses the DHCP snooping binding table to validate the source IP address of packets received on a port.
Option A is correct because IP Source Guard (IPSG) relies on the DHCP snooping binding table (and optionally static IP source bindings) to check that the source IP address of frames arriving on an untrusted port matches an entry, dropping spoofed traffic. Option B is correct because IPSG is often deployed together with port security: port security validates source MAC addresses while IPSG validates source IP addresses, giving combined Layer 2/Layer 3 source filtering. Option C is wrong because IPSG also supports manually configured static IP source bindings via the 'ip source binding' command, so it is not limited to DHCP-assigned addresses. Option D is wrong because IPSG inspects the source IP address (and source MAC), not the destination MAC address. Option E is wrong because IPSG does not require 802.1X; it depends on DHCP snooping or static bindings, and 802.1X is an independent access-control feature.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
IP Source Guard uses the DHCP snooping binding table to validate the source IP address of packets received on a port.
Why this is correct
IP Source Guard permits traffic only when the packet's source IP matches an entry in the DHCP snooping binding table for that port, dropping spoofed addresses. This binds source IP to switch port and MAC.
- ✓
IP Source Guard can be configured with port security to provide additional MAC address filtering.
Why this is correct
IP Source Guard filters traffic using the DHCP snooping binding table, validating source IP against port. Combining it with port security adds MAC address checking, so spoofed frames with mismatched IP or MAC pairs are dropped.
- ✗
IP Source Guard only works with DHCP-assigned IP addresses, not static IP addresses.
Why it's wrong here
IP Source Guard also supports static IP source bindings configured manually, so it does not depend solely on DHCP snooping entries. It is tempting because DHCP snooping integration is the most common deployment, and dynamic binding is the typical exam example, but static hosts are covered via explicit ip source binding commands.
- ✗
IP Source Guard filters traffic based on the destination MAC address.
Why it's wrong here
IP Source Guard inspects the source IP and source MAC of ingress frames, not the destination MAC. It is tempting because MAC filtering is a familiar Layer 2 control, and destination-MAC-based forwarding decisions belong to normal switch CAM-table lookup, not source validation.
- ✗
IP Source Guard requires 802.1X authentication to be enabled on the port.
Why it's wrong here
IP Source Guard validates the source IP and MAC against the DHCP snooping binding table or a static entry, so it functions without any 802.1X deployment. The claim is tempting because 802.1X also filters traffic by identity at the port, making it the right control when port-based user authentication is the actual requirement.
Visual reference
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
Wireless Deployment Models and Security
Key term
Cisco TrustSec
Cisco TrustSec is a security architecture that uses identity-based access control and encryption to protect network traffic, rather than relying only on IP addresses and VLANs.
Key term
IP Source Guard
IP Source Guard is a network security feature that blocks IP address spoofing by verifying that each packet's source IP address matches an authorized binding assigned to that switch port.
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.