
CiscoCertified Network Associate (CCNA)
Domain 5Objective 7
5.7 Configure and Verify Layer 2 Security Features (DHCP Snooping, Dynamic ARP Inspection, and Port Security) 200-301 Practice Questions (Page 1)
Part of the Security Fundamentals domain, which accounts for 15% of the 200-301 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~8–12 in this domain), expect 1–1 from this objective — we provide 21 practice questions to prepare you well beyond it. (estimate)
21questions here
5free pages
7concepts
15%of the exam
Questions 1–5
- 1
Which Layer 2 security feature uses the DHCP snooping binding table to validate ARP packets and prevent ARP spoofing?
Select an answer first - 2
What is the first step in configuring Dynamic ARP Inspection (DAI) on a switch?
Select an answer first - 3
A switch port has port security configured with maximum 3 and violation shutdown. A user connects a hub with three devices, and the port goes into err-disabled state. The administrator wants to restore the port without changing the security policy. What should the administrator do?
Select an answer first - 4
A company has a conference room with a wall jack that is used by visitors. The port is configured with port security maximum 3 and violation shutdown. During a meeting, a visitor connects a laptop, a tablet, and a smartphone to the port using a small switch. The port goes into err-disabled state. The administrator wants to allow up to three devices on that port but avoid future outages. What should the administrator do?
Select an answer first - 5
Which port security violation mode shuts down the port and places it in the err-disabled state?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “200-301” is a trademark of its owner, used for identification only.