Which THREE of the following are effective techniques to prevent ARP poisoning attacks? (Choose three.)
Configuring port security on switches is an effective technique because it limits the number of MAC addresses that can be learned on a specific switch port. By restricting a port to a single, legitimate MAC address or a small, defined set, it prevents an attacker from introducing a new, spoofed MAC address to impersonate another device or the gateway, thereby mitigating ARP poisoning attempts that rely on MAC address changes.
Why this answer
Configuring port security on switches is effective against ARP poisoning because it limits the number of MAC addresses allowed on a port, preventing an attacker from flooding the network with spoofed MAC addresses. By restricting the port to a single or limited set of MAC addresses, it stops unauthorized devices from injecting fake ARP replies. This is a Layer 2 security control that directly mitigates the ability to perform ARP cache poisoning at the access edge.
Exam trap
The trap here is that candidates often confuse DHCP snooping as a direct ARP poisoning prevention technique, when in fact it only provides the binding table that DAI uses, and without DAI enabled, DHCP snooping alone does not inspect or block malicious ARP packets.