This drag-and-drop item maps common Layer 2 and access-layer threats to their mitigation controls. Dynamic ARP Inspection protects against ARP spoofing or poisoning by validating ARP packets against trusted binding information. DHCP snooping blocks rogue DHCP behavior and builds the binding table used by other protections. BPDU Guard protects PortFast edge ports by err-disabling a port that receives an unexpected spanning-tree BPDU, which helps prevent rogue switch insertion. A nondefault or unused native VLAN, combined with disabling DTP and manually configuring trunks, reduces VLAN hopping exposure. Cisco CCNA 200-301 v1.1 Security Fundamentals and Network Access both touch these controls because many campus attacks happen before traffic ever reaches a firewall. The dependable way to solve the matching is to identify the abused protocol: ARP attacks map to DAI, DHCP attacks map to DHCP snooping, unexpected switch/STP participation maps to BPDU Guard, and trunk/native-VLAN abuse maps to VLAN-hopping mitigation.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit