DHCP Snooping MAC Address Verification Drop Conditions
An engineer is configuring DHCP on a Cisco switch and wants to ensure that a DHCP packet will be dropped. Under which condition will this occur?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The core concept is DHCP snooping security features, specifically the trap of confusing general DHCP behavior with specific anti-spoofing validation rules.
This question tests DHCP snooping configuration and packet validation logic on Cisco switches. It establishes that packets are dropped when source MAC and client hardware address mismatches occur on untrusted interfaces.
Candidates often select Option D because they misinterpret the role of a relay agent or confuse it with invalid IP scenarios, failing to recognize that Option C describes a definitive security violation caught by snooping.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Option C is correct because DHCP snooping includes a feature called 'MAC address verification'. When enabled, the switch compares the source MAC address in the Ethernet header with the Client Hardware Address (ciaddr) in the DHCP payload. If these do not match on an untrusted port, the packet is considered spoofed and is dropped.Why the Other Options Are Wrong
Option A is incorrect; receiving a DHCP offer from inside the network is expected behavior if the server is trusted. Option B is incorrect because DHCP snooping does not drop all packets by default; it only drops unauthorized offers from untrusted ports unless the binding table is explicitly used for enforcement, but even then, it doesn't drop all packets indiscriminately. Option D is incorrect because a relay-agent IP of 0.0.0.0 is typically valid in certain initial discovery phases or specific relay configurations, not an automatic drop condition like a MAC mismatch.Community Comment Notes
The community overwhelmingly agrees with Option C. One user noted that while the question phrasing might seem ambiguous ('ensuring a packet will be dropped'), Option C represents the most logical security trigger for DHCP snooping. Another commenter highlighted that without the context of 'DHCP Snooping', the question is confusing, but with that context, C is the clear technical answer for packet validation failure.Exam Strategy
When answering DHCP snooping questions, always look for keywords like 'untrusted interface' and 'verification'. Remember that the primary purpose of snooping is to build a binding table and prevent rogue servers, with MAC verification being a key anti-spoofing mechanism.
Frequently Asked Questions
What triggers DHCP snooping to drop a packet based on MAC?
It triggers when the source MAC in the Ethernet frame differs from the Client Hardware Address in the DHCP payload on an untrusted port.
Does DHCP snooping block all DHCP traffic initially?
No, it only blocks DHCP offers/acks from untrusted ports. Other DHCP messages like Discover/Request are allowed to pass through.