Question 1 of 30
In a corporate network, a network engineer is tasked with implementing Dynamic ARP Inspection (DAI) to enhance security against ARP spoofing attacks. The engineer configures DAI on a VLAN that has multiple switches and hosts. During testing, the engineer notices that legitimate ARP requests from a specific host are being dropped, while ARP requests from other hosts are processed normally. The engineer checks the DHCP snooping binding table and finds that the MAC address of the problematic host is not listed. What could be the most likely reason for the legitimate ARP requests being dropped, and how should the engineer resolve this issue?
The host's IP address is not associated with its MAC address in the DHCP snooping binding table, which is required for DAI to validate ARP packets.
The VLAN configuration on the switches is incorrect, causing the ARP packets to be misrouted.
The ARP requests are being sent from a different subnet, which is not allowed by the DAI configuration.
The DAI feature is not enabled on the switch ports connected to the problematic host.

Preparing for CISCO 300-620 Implementing Cisco Application Centric Infrastructure (DCACI)? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free