PrepAway - Latest Free Exam Questions & Answers

What is the purpose of this global configuration command made on R1?

On a Company switch named R1 you configure the following:
ip arp inspection vlan 10-12, 15
What is the purpose of this global configuration command made on R1?

PrepAway - Latest Free Exam Questions & Answers

A.
Discards ARP packets with invalid IP-to-MAC address bindings on trusted ports

B.
Validates outgoing ARP requests for interfaces configured on VLAN 10, 11, 12, or 15

C.
Intercepts, logs, and discards ARP packets with invalid IP-to-MAC address bindings

D.
Intercepts all ARP requests and responses on trusted ports

E.
None of the other alternatives apply

Explanation:
The “ip arp inspection” command enables Dynamic ARP Inspection (DAI) for the specified
VLANs. DAI is a security feature that validates Address Resolution Protocol (ARP) packets
in a network. DAI allows a network administrator to intercept, log, and discard ARP packets
with invalid MAC address to IP address bindings. This capability protects the network from
certain “man-in-the-middle” attacks.
Reference:
http://www.cisco.com/en/US/docs/switches/lan/catalyst4500/12.1/20ew/configuration/guide/d
ynarp.html


Leave a Reply