✔The Best Protection Against MITM and Spoofing Attacks:
✅(D) Associating DHCP Snooping with IPSG (IP Source Guard) and DAI (Dynamic ARP Inspection)providescomplete protectionby:
Blocking rogue DHCP servers.
Preventing MAC/IP spoofing.
Ensuring only valid clients access the network.
✔Why Not Other Options?
❌(A) Configuring trusted/untrusted interfacesonly helpsblock rogue DHCP servers, but does not prevent spoofing.
❌(B) Limiting MAC address learningprevents MAC flooding, but does not stopMITM attacks.
❌(C) Checking the CHADDR field in DHCP Snoopinghelps detectspoofed requests, but does not block all MITM scenarios.
????Reference:Huawei HCIE Datacom – Security Mechanisms for Intranet Protection
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit