GSEC Networking and Protocols Practice Question
An administrator needs to harden a corporate switch infrastructure against unauthorized device connections and Man-in-the-Middle attacks. Which combination of Layer 2 security controls provides the most comprehensive defense against both DHCP spoofing and ARP poisoning?
⚠ Common exam trap
Candidates often select Port Security alone. While Port Security limits MAC addresses, it does not validate the content of ARP packets or DHCP traffic, leaving the network vulnerable to spoofing and poisoning.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploying Dynamic ARP Inspection paired with an active DHCP Snooping binding table.
DHCP Snooping builds a trusted binding database by intercepting DHCP messages on untrusted ports, while Dynamic ARP Inspection utilizes this database to drop forged ARP replies. Implementing both mitigates rogue DHCP servers and prevents ARP cache poisoning attacks, securing Layer 2 communications from interception and spoofing without relying solely on static configurations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Implementing Port Security along with Static ARP entries on all critical endpoints.
Why it's wrong here
Port Security limits MAC address learning per interface, but it fails to inspect ARP payloads or prevent malicious DHCP allocation. Static ARP entries do not scale in enterprise environments and cannot prevent dynamic ARP poisoning attacks launched by sophisticated malicious actors.क्क
- ✗
Enabling BPDU Guard and Root Guard on all designated edge access ports.
Why it's wrong here
BPDU Guard and Root Guard protect the Spanning Tree Protocol topology from unauthorized switches attempting to become the root bridge. These mechanisms do not validate IP-to-MAC bindings or inspect DHCP traffic, leaving the network vulnerable to ARP spoofing and rogue IP assignment.क्क
- ✓
Deploying Dynamic ARP Inspection paired with an active DHCP Snooping binding table.
Why this is correct
DHCP Snooping tracks legitimate IP-to-MAC address assignments by monitoring untrusted switch ports. Dynamic ARP Inspection references this verified database to intercept and drop malicious ARP packets, successfully preventing both DHCP spoofing and man-in-the-middle ARP cache poisoning attempts.क्क
- ✗
Configuring VLAN Access Control Lists alongside private VLAN isolated port modes.
Why it's wrong here
Private VLANs and VACLs restrict inter-port communication within the same VLAN and filter traffic based on network layers. However, they lack the ability to inspect dynamic ARP packets or validate DHCP lease allocations against a trusted database to prevent spoofing.क्क
Visual reference
About these practice questions
Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.