SSCP Network and Communications Security Practice Question
A security engineer is hardening a data center network against VLAN hopping attacks. The core switches currently use 802.1Q trunking on all inter-switch links, and unused access ports are left in the default VLAN. Which configuration change best mitigates VLAN hopping while preserving legitimate trunk operation?
⚠ Common exam trap
The trap here is assuming that Spanning Tree protection features such as BPDU Guard or Root Guard also prevent VLAN hopping, when they actually address a different attack class.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Disable Dynamic Trunking Protocol (DTP) on all access ports and place unused ports in an unused VLAN.
VLAN hopping typically relies on DTP negotiation on an access port or on double tagging through the native VLAN. Disabling DTP on access ports stops an attacker from forming a trunk, and moving unused ports to an unused VLAN removes an easy double-tagging target. Legitimate trunks remain functional on trusted inter-switch links, so segmentation is preserved while the attack surface is reduced.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Disable Dynamic Trunking Protocol (DTP) on all access ports and place unused ports in an unused VLAN.
Why this is correct
Disabling DTP prevents an attacker from negotiating a trunk on an access port, and moving unused ports out of the default VLAN removes a common double-tagging target. This preserves legitimate trunks on trusted links while closing the two main VLAN hopping vectors: switch spoofing and double tagging against the native VLAN.
- ✗
Change all access ports to trunk ports and enable Dynamic Trunking Protocol (DTP) negotiation.
Why it's wrong here
Enabling DTP on access ports allows an attacker to negotiate a trunk and reach other VLANs, which is the core of VLAN hopping. Trunk ports also carry tagged frames that can be double-tagged. This change increases exposure rather than reducing it, and it contradicts the goal of limiting trunk negotiation to trusted inter-switch links.
- ✗
Enable BPDU Guard and Root Guard on all trunk ports to block VLAN hopping frames.
Why it's wrong here
BPDU Guard and Root Guard protect the Spanning Tree Protocol topology from rogue switches; they do not stop 802.1Q double tagging or DTP-based trunk negotiation. An attacker can still send double-tagged frames or negotiate a trunk on an access port if DTP remains enabled. These features address a different layer of switch security.
- ✗
Configure all inter-switch links as access ports in VLAN 1 to simplify the topology.
Why it's wrong here
Converting inter-switch links to access ports in VLAN 1 collapses segmentation and prevents legitimate VLAN traffic from crossing switches. It also places all devices in the default VLAN, which is the exact condition double tagging exploits. This approach destroys the intended network design and does not mitigate VLAN hopping.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.