DHCP Snooping tracks legitimate IP-to-MAC address assignments by monitoring untrusted switch ports. Dynamic ARP Inspection references this verified database to intercept and drop malicious ARP packets, successfully preventing both DHCP spoofing and man-in-the-middle ARP cache poisoning attempts.क्क
Why this answer
DHCP Snooping builds a trusted binding database by intercepting DHCP messages on untrusted ports, while Dynamic ARP Inspection utilizes this database to drop forged ARP replies. Implementing both mitigates rogue DHCP servers and prevents ARP cache poisoning attacks, securing Layer 2 communications from interception and spoofing without relying solely on static configurations.
Exam trap
Candidates often select Port Security alone. While Port Security limits MAC addresses, it does not validate the content of ARP packets or DHCP traffic, leaving the network vulnerable to spoofing and poisoning.