Courseiva
hardMultiple Select

350-401 Practice Question: Which two statements about DHCP snooping are…

Which two statements about DHCP snooping are true? (Choose two.)

⚠ Common exam trap

Cisco often tests the direction of trust — candidates instinctively trust the client-facing port (where the user is) instead of the server-facing uplink, which inverts the entire security model.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

DHCP snooping treats all ports as untrusted by default, except those explicitly configured as trusted.

Option A is correct because DHCP snooping's default security posture is to treat every port as untrusted, so only ports explicitly configured with the ip dhcp snooping trust command (typically uplinks toward the legitimate DHCP server) are allowed to carry server-originated DHCP messages such as OFFER, ACK, and NAK. Option C is correct because DHCP snooping inspects DHCP traffic and populates a binding table that records the client MAC address, leased IP address, VLAN, lease time, and ingress switch port, which is later used by features like Dynamic ARP Inspection and IP Source Guard. Option B is incorrect because the ip dhcp snooping trust command is applied to ports facing the trusted DHCP server or uplink, not to ports connected to DHCP clients, which must remain untrusted. Option D is incorrect because DHCP snooping must be enabled per VLAN with the ip dhcp snooping vlan command after the global ip dhcp snooping command; global enablement alone does not activate snooping on any VLAN. Option E is incorrect because DHCP snooping does not drop all packets containing option 82 from untrusted ports; it typically strips or replaces option 82 information on untrusted ports and can be configured to allow or drop such packets, so a blanket drop is not accurate.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    DHCP snooping treats all ports as untrusted by default, except those explicitly configured as trusted.

    Why this is correct

    DHCP snooping's default trust model marks every switch port untrusted, so DHCP server replies arriving on access ports are dropped; only uplinks or server-facing ports are explicitly trusted. This satisfies the stem's requirement for a true statement about DHCP snooping.

  • ✗

    The ip dhcp snooping trust command is applied on ports connected to DHCP clients.

    Why it's wrong here

    Trust is configured on ports facing legitimate DHCP servers or uplinks, not client-facing access ports, which must remain untrusted so offer and ACK messages are filtered. It is tempting because administrators do apply trust commands per interface, and trusting a port would be correct when a downstream switch or server legitimately relays DHCP.

  • ✓

    DHCP snooping builds a binding database that maps client MAC addresses, IP addresses, VLAN, and port information.

    Why this is correct

    DHCP snooping inspects DHCP messages and records each lease in a binding table keyed on client MAC address, leased IP address, VLAN and ingress switch port. This database is what later enables rate limiting and blocking of rogue DHCP servers or spoofed replies on untrusted ports.

  • ✗

    DHCP snooping can be configured globally without enabling it on specific VLANs.

    Why it's wrong here

    DHCP snooping requires explicit VLAN enablement; global configuration alone leaves VLANs unprotected. It is tempting because many Cisco features accept global commands that apply broadly, and global-only configuration would be correct only where the platform's default VLAN coverage matched the intended scope.

  • ✗

    DHCP snooping drops all DHCP packets that contain option 82 information from untrusted ports.

    Why it's wrong here

    DHCP snooping permits option 82 from trusted ports and inserts or forwards it; it does not drop all option 82 packets from untrusted ports. The feature instead blocks rogue DHCP server offers and rate-limits requests. The statement tempts because option 82 relates to relay agent information, but snooping handles it differently.

Visual reference

Client DHCP Server 1 Discover (broadcast) 2 Offer (IP: 192.168.1.10) 3 Request (I accept) 4 Acknowledge (lease confirmed) DORA — the four-step DHCP lease process

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

Go deeper

Related to this question

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.