📖 What is DHCP Snooping?

DHCP Snooping is a Layer 2 security feature that acts like a firewall between untrusted hosts and trusted DHCP servers. It prevents rogue DHCP servers from assigning incorrect IP addresses to clients by filtering unauthorized DHCP messages.

🥋 Sensei Says:

"This is specifically designed to stop 'Man-in-the-Middle' attacks. The switch builds a binding table of trusted MAC and IP addresses to enforce this."

📚 Certification: CompTIA Network+ Certification Exam (N10-009)

🔑 What are the Key Concepts of DHCP Snooping?

  • Trusted and Untrusted Ports: Administrators designate ports connected to legitimate DHCP servers as trusted, while all other user-facing ports are set to untrusted by default.
  • DHCP Binding Database: The switch maintains a dynamic table mapping MAC addresses to assigned IP addresses, lease times, and VLANs to validate network traffic.
  • Rogue Server Mitigation: The feature blocks DHCP-OFFER and DHCP-ACK messages from entering untrusted ports, preventing unauthorized servers from assigning incorrect network configurations.
  • MitM Attack Prevention: By ensuring only authorized servers provide IP and gateway information, it stops attackers from redirecting traffic through a malicious device.
  • Synergy with DAI: DHCP Snooping provides the foundational binding table used by Dynamic ARP Inspection (DAI) to prevent ARP poisoning and IP spoofing attacks.

🎯 How does DHCP Snooping appear on the N10-009 Exam?

You may be asked to identify the best Layer 2 security mechanism to implement after discovering that an employee plugged a home router into a wall jack, causing IP conflicts.

A scenario might describe a need to prevent Man-in-the-Middle attacks where an attacker is providing false default gateway information to clients; you must select DHCP Snooping as the solution.

Expect questions where you must distinguish between trusted and untrusted ports, specifically identifying which port type should be assigned to a legitimate DHCP server to ensure connectivity.

❓ Frequently Asked Questions

Can DHCP Snooping prevent ARP spoofing on its own?

No, DHCP Snooping only prevents rogue DHCP servers. However, it creates the binding database that Dynamic ARP Inspection (DAI) uses to verify ARP packets and stop spoofing.


What is the primary risk of misconfiguring a port as untrusted when a server is connected?

If a legitimate DHCP server is on an untrusted port, the switch will drop its DHCP-OFFER messages, preventing all clients on that switch from receiving IP addresses.

Related Terms from CompTIA Network+ Certification Exam

📝 Related Study Guides

Exam Tips 8 min read

CompTIA Network+ (N10-009): Exam Format, Domains & Tips

The CompTIA Network+ N10-009 exam contains up to 90 questions in 90 minutes, requiring 720 out of 900 to pass. It covers five domains: Networking Fundamentals (23%), Network Implementation (20%), Network Operations (18%), Network Security (19%), and Network Troubleshooting (20%). Expect multiple choice, multiple select, and performance-based questions testing hands-on networking skills.

Exam Tips 10 min read

CompTIA Network+ (N10-009): Exam Format, Domains & Tips

The CompTIA Network+ (N10-009) exam consists of a maximum of 90 questions, including multiple-choice and performance-based questions (PBQs), with a 90-minute time limit. To pass, you must master five core domains: Networking Fundamentals, Implementations, Operations, Security, and Troubleshooting, focusing heavily on real-world scenario application.

Exam Tips 10 min read

CompTIA Network+ (N10-009): What to Expect on the Exam

The CompTIA Network+ (N10-009) exam consists of a maximum of 90 questions, including multiple-choice and performance-based questions (PBQs), with a 90-minute time limit. You must master five core domains—Networking Fundamentals, Implementations, Operations, Security, and Troubleshooting—to achieve a passing score of 720 on a scale of 100-900.

🧠

Test Your Knowledge

Think you understand DHCP Snooping? Put it to the test with our practice exam.

Try 10 Free Questions

⭐ 1,000 expert-curated questions available with Premium

Upgrade Premium