Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 200-301 Exam - Topic 2 Question 75 Discussion

What is used to identify spurious DHCP servers?
D) DHCPOFFER
A) DHCPREQUEST
B) DHCPDISCOVER
C) DHCPACK

Cisco 200-301 Exam - Topic 2 Question 75 Discussion

Actual exam question for Cisco's 200-301 exam
Question #: 75
Topic #: 2
[All 200-301 Questions]

What is used to identify spurious DHCP servers?

Show Suggested Answer Hide Answer
Suggested Answer: D

DHCPOFFER is used to identify spurious DHCP servers. A spurious DHCP server is any device that is configured to act as a DHCP server without the network administrator's knowledge or permission. A spurious DHCP server can cause network problems by assigning incorrect or duplicate IP addresses to clients, or by redirecting traffic to malicious gateways.To prevent such attacks, the DHCP snooping feature can be enabled on switches to filter out invalid or unauthorized DHCP messages from untrusted sources1.

DHCP snooping works by intercepting and validating DHCP messages on a per-VLAN basis.The switch maintains a DHCP snooping binding database that contains information about the trusted hosts with leased IP addresses, such as MAC address, IP address, lease time, binding type, VLAN number, and interface information2. The switch also classifies its ports as trusted or untrusted. Trusted ports are those that connect to authorized DHCP servers or other trusted switches. Untrusted ports are those that connect to untrusted hosts or devices.The switch only allows DHCP messages from trusted ports, and drops any DHCP messages from untrusted ports that do not match the information in the binding database3.

The switch uses DHCPOFFER messages to identify spurious DHCP servers. A DHCPOFFER message is a response from a DHCP server to a client's request for an IP address.The message contains the offered IP address, subnet mask, default gateway, and other configuration parameters for the client4. When the switch receives a DHCPOFFER message from an untrusted port, it compares the source MAC address and the offered IP address with the binding database. If there is no match, the switch considers the message as coming from a spurious DHCP server and drops it.The switch also logs an error message and increments a counter for the number of dropped messages5.


1: Configuring DHCP Snooping - Cisco

2: Catalyst 6500 Release 12.2SX Software Configuration Guide - DHCP Snooping Binding Database

3: What is DHCP Snooping? - IONOS

4: Dynamic Host Configuration Protocol (DHCP) and Bootstrap Protocol (BOOTP) Parameters

5: Configuring DHCP Snooping - Cisco

Contribute your Thoughts:

0/2000 characters
Lea
9 months ago
Yup, DHCPDISCOVER is the first step in finding those spurious servers!
upvoted 0 times
...
Ty
10 months ago
Wait, are we sure about that? I thought DHCPACK had a role too.
upvoted 0 times
...
Iola
10 months ago
I agree, DHCPDISCOVER is the way to go!
upvoted 0 times
...
Kenneth
10 months ago
I thought it was DHCPREQUEST? Seems like a common misconception.
upvoted 0 times
...
Roslyn
10 months ago
It's definitely DHCPDISCOVER that helps identify rogue servers.
upvoted 0 times
...
Judy
10 months ago
I thought DHCPACK was more about confirming leases rather than identifying spurious servers. This is tricky!
upvoted 0 times
...
Leatha
11 months ago
I feel like DHCPOFFER might be the key to spotting rogue servers, but I could be mixing it up with something else we studied.
upvoted 0 times
...
Pamella
11 months ago
I remember practicing a question where DHCPREQUEST was mentioned, but I can't recall if that's the right answer for this one.
upvoted 0 times
...
Maryann
11 months ago
I think we talked about DHCPDISCOVER being used to find servers, but I'm not sure if it identifies spurious ones.
upvoted 0 times
...
Ashlee
11 months ago
Okay, let me think this through step-by-step. The client sends a DHCPDISCOVER to find available DHCP servers, then selects one by sending a DHCPREQUEST. So the message used to identify spurious servers must be DHCPREQUEST. I'm confident that's the right answer.
upvoted 0 times
...
Veronika
11 months ago
Ah, I remember learning about this in class. The key is to identify the message that a client uses to verify the DHCP server it's communicating with. I think the answer is DHCPREQUEST.
upvoted 0 times
...
Ty
11 months ago
Hmm, I'm a little unsure about this one. I know DHCP is used for IP address assignment, but I can't quite remember which message is used to identify spurious servers. I'll have to think this through carefully.
upvoted 0 times
...
Dean
11 months ago
This one seems pretty straightforward. I'm pretty sure the answer is DHCPDISCOVER, since that's the message a client sends to identify and select a DHCP server.
upvoted 0 times
...
Cassie
11 months ago
The permissions and user access seem like the most critical part of this. I'll make sure to double-check that the agents have the right privileges to place orders on behalf of customers.
upvoted 0 times
...
Keneth
11 months ago
I feel like I've seen a question like this before. I think bribery might be more specific, but corruption could work, too.
upvoted 0 times
...
Reid
11 months ago
Hmm, I'm a bit unsure about this one. I'll need to think it through carefully. The scenarios seem similar, but I'm not sure which one specifically points to a rationalization as the root cause.
upvoted 0 times
...
Georgiana
2 years ago
Haha, you guys are really overthinking this. It's gotta be DHCPOFFER - that's the message the servers send out offering an IP address. If the client gets offers from more than one, it knows something fishy is going on!
upvoted 0 times
Filiberto
2 years ago
Correct!
upvoted 0 times
...
Bulah
2 years ago
Got it. So, the answer is B) DHCPDISCOVER, not DHCPOFFER.
upvoted 0 times
...
Clorinda
2 years ago
By checking the offers it receives. If it gets offers from multiple servers, it means there might be a rogue server.
upvoted 0 times
...
Cyril
2 years ago
Hmm, I see. So, how does the client know if there's a spurious DHCP server?
upvoted 0 times
...
Carolynn
2 years ago
B) DHCPDISCOVER
upvoted 0 times
...
Alpha
2 years ago
Actually, it's not DHCPOFFER. It's B) DHCPDISCOVER. That's the message the client sends out looking for an IP address.
upvoted 0 times
...
Jacklyn
2 years ago
D) DHCPOFFER
upvoted 0 times
...
...
Mayra
2 years ago
Ah, I see where you're both coming from. But what about DHCPACK? Isn't that the message the server sends back to confirm the IP address allocation? If the client gets multiple DHCPACK responses, that would definitely flag some rogue DHCP servers, right?
upvoted 0 times
...
Suzan
2 years ago
Hmm, I'm not so sure. DHCPDISCOVER might work, but I was thinking DHCPREQUEST would be a better option. When the client requests an IP address, it could compare the responses and identify any servers that aren't the legitimate one.
upvoted 0 times
...
Shawn
2 years ago
This question seems pretty straightforward. I think the answer is DHCPDISCOVER. That's the message a client sends out to find available DHCP servers, so if it gets responses from multiple servers, that would identify them as potentially spurious.
upvoted 0 times
...

Save Cancel