Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 350-701 Exam - Topic 1 Question 129 Discussion

[Security Concepts]A network administrator configures Dynamic ARP Inspection on a switch. After Dynamic ARP Inspection is applied, all users on that switch are unable to communicate with any destination. The network administrator checks the interface status of all interfaces, and there is no err-disabled interface. What is causing this problem?
D) The no ip arp inspection trust command is applied on all user host interfaces
A) DHCP snooping has not been enabled on all VLANs.
B) The ip arp inspection limit command is applied on all interfaces and is blocking the traffic of all users.
C) Dynamic ARP Inspection has not been enabled on all VLANs

Cisco 350-701 Exam - Topic 1 Question 129 Discussion

Actual exam question for Cisco's 350-701 exam
Question #: 129
Topic #: 1
[All 350-701 Questions]

[Security Concepts]

A network administrator configures Dynamic ARP Inspection on a switch. After Dynamic ARP Inspection is applied, all users on that switch are unable to communicate with any destination. The network administrator checks the interface status of all interfaces, and there is no err-disabled interface. What is causing this problem?

Show Suggested Answer Hide Answer
Suggested Answer: D

Dynamic ARP inspection (DAI) is a security feature that validates ARP packets in a network. It intercepts, logs, and discards ARP packets with invalid IP-to-MAC address bindings. This capability protects the network from certain man-in-the-middle attacks. After enabling DAI, all ports become untrusted ports.


Contribute your Thoughts:

0/2000 characters
Kallie
2 days ago
I feel like B could be the issue. The limit command might be too strict.
upvoted 0 times
...
Magdalene
7 days ago
I think it's option A. Without DHCP snooping, ARP packets get dropped.
upvoted 0 times
...
Domingo
12 days ago
Wait, how can all users lose communication just like that? Sounds weird!
upvoted 0 times
...
Galen
17 days ago
No way, it has to be D) with that trust command messing things up.
upvoted 0 times
...
Tresa
23 days ago
C) Dynamic ARP Inspection not enabled on all VLANs makes sense.
upvoted 0 times
...
Francesco
28 days ago
I think it's B) that's blocking the traffic.
upvoted 0 times
...
Niesha
1 month ago
A) DHCP snooping not enabled on all VLANs could be the issue.
upvoted 0 times
...
Shoshana
1 month ago
I vaguely recall that if the trust command is not applied, it could cause issues. So maybe option D is the right answer?
upvoted 0 times
...
Tish
1 month ago
I feel like I came across a similar question where enabling DAI on all VLANs was crucial. Could it be option C?
upvoted 0 times
...
Lorenza
2 months ago
I’m not entirely sure, but I think if the ip arp inspection limit is set too low, it could block traffic. That might be option B?
upvoted 0 times
...
Lovetta
2 months ago
I remember studying that Dynamic ARP Inspection relies on DHCP snooping to function properly, so maybe it's option A?
upvoted 0 times
...

Save Cancel