hardMultiple Select
350-401 Practice Question: Which two statements about DHCP snooping are…
Which two statements about DHCP snooping are true? (Choose two.)
⚠ Common exam trap
Cisco often tests the direction of trust — candidates instinctively trust the client-facing port (where the user is) instead of the server-facing uplink, which inverts the entire security model.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
DHCP snooping treats all ports as untrusted by default, except those explicitly configured as trusted.
Option A is correct because DHCP snooping's default security posture is to treat every port as untrusted, so only ports explicitly configured with the ip dhcp snooping trust command (typically uplinks toward the legitimate DHCP server) are allowed to carry server-originated DHCP messages such as OFFER, ACK, and NAK. Option C is correct because DHCP snooping inspects DHCP traffic and populates a binding table that records the client MAC address, leased IP address, VLAN, lease time, and ingress switch port, which is later used by features like Dynamic ARP Inspection and IP Source Guard. Option B is incorrect because the ip dhcp snooping trust command is applied to ports facing the trusted DHCP server or uplink, not to ports connected to DHCP clients, which must remain untrusted. Option D is incorrect because DHCP snooping must be enabled per VLAN with the ip dhcp snooping vlan command after the global ip dhcp snooping command; global enablement alone does not activate snooping on any VLAN. Option E is incorrect because DHCP snooping does not drop all packets containing option 82 from untrusted ports; it typically strips or replaces option 82 information on untrusted ports and can be configured to allow or drop such packets, so a blanket drop is not accurate.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
DHCP snooping treats all ports as untrusted by default, except those explicitly configured as trusted.
Why this is correct
DHCP snooping's default trust model marks every switch port untrusted, so DHCP server replies arriving on access ports are dropped; only uplinks or server-facing ports are explicitly trusted. This satisfies the stem's requirement for a true statement about DHCP snooping.
- ✗
The ip dhcp snooping trust command is applied on ports connected to DHCP clients.
Why it's wrong here
Trust is configured on ports facing legitimate DHCP servers or uplinks, not client-facing access ports, which must remain untrusted so offer and ACK messages are filtered. It is tempting because administrators do apply trust commands per interface, and trusting a port would be correct when a downstream switch or server legitimately relays DHCP.
- ✓
DHCP snooping builds a binding database that maps client MAC addresses, IP addresses, VLAN, and port information.
Why this is correct
DHCP snooping inspects DHCP messages and records each lease in a binding table keyed on client MAC address, leased IP address, VLAN and ingress switch port. This database is what later enables rate limiting and blocking of rogue DHCP servers or spoofed replies on untrusted ports.
- ✗
DHCP snooping can be configured globally without enabling it on specific VLANs.
Why it's wrong here
DHCP snooping requires explicit VLAN enablement; global configuration alone leaves VLANs unprotected. It is tempting because many Cisco features accept global commands that apply broadly, and global-only configuration would be correct only where the platform's default VLAN coverage matched the intended scope.
- ✗
DHCP snooping drops all DHCP packets that contain option 82 information from untrusted ports.
Why it's wrong here
DHCP snooping permits option 82 from trusted ports and inserts or forwards it; it does not drop all option 82 packets from untrusted ports. The feature instead blocks rogue DHCP server offers and rate-limits requests. The statement tempts because option 82 relates to relay agent information, but snooping handles it differently.
Visual reference
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
Learn chapter
ACLs and Infrastructure Security Features
Key term
IP Source Guard
IP Source Guard is a network security feature that blocks IP address spoofing by verifying that each packet's source IP address matches an authorized binding assigned to that switch port.
Key term
L2 Security Features
L2 Security Features are network security mechanisms that operate at Layer 2 of the OSI model to protect local network traffic from threats like MAC spoofing, ARP attacks, and unauthorized access.
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.