CERTIVIEW

Friday, 27 November 2015

CCNP Security Question of the Week: DHCP Server Service

ccnpQoW04

A network printer has a DHCP server service that cannot disable. How can you configure a layer 2 switch to block the printer from causing any issues on the network?

A. Remove the ip helper-address
B. Configure an ACL to block outbound TCP port 68
C. Configure DHCP snooping
D. Configure port-security

Reveal Answer

Answer: C.

Removing the helper address won’t stop any devices within the VLAN from seeing the DHCP server on the printer.  Although port 68 is used for DHCP, blocking in the outbound direction would not stop DHCP from functioning…inbound would.  Port security would lock the port down to the single MAC address of the printer, the DHCP server built into the printer would use the same MAC, so there would be no effect.  Enabling DHCP snooping would make all port untrusted for a DHCP server, therefore all offers would be dropped by the which before they could get to the clients.

Related Resources
Cisco White Papers

Related Course
CCNP Security e-Camp

CCNP Security Question of the Week Series

  • CCNP Security Question of the Week: Cisco ASA Security Context
  • CCNP Security Question of the Week: Authenticating ASDM Users
  • CCNP Security Question of the Week: Layer 5–7 Policy Maps
  • CCNP Security Question of the Week: 802.1X
  • CCNP Security Question of the Week: IPS Updates
  • CCNP Security Question of the Week: IPsec VPN Tunnels
  • CCNP Security Question of the Week: AnyConnect VPN Client
  • CCNP Security Question of the Week: ASA AIP-SSM and ASA AIP-SSC
  • CCNP Security Question of the Week: Disable DHCP Server Service
  • CCNP Security Question of the Week: Cisco ASA Security Appliance Access List
  • CCNP Security Question of the Week: Network Address Translation
  • CCNP Security Question of the Week: Harden a Switch
  • CCNP Security Question of the Week: SSH Login
  • CCNP Security Question of the Week: Packet-Tracer Command
  • CCNP Security Question of the Week: SSL Ciphers
  • CCNP Security Question of the Week: VLAN Hopping
  • CCNP Security Question of the Week: DHCP Server Service


from
CERTIVIEW
Unknown at 04:13
Share

No comments:

Post a Comment

‹
›
Home
View web version

About Me

Unknown
View my complete profile
Powered by Blogger.