DHCP Snooping MAC Address Verification Drop Conditions

Configure network infrastructure security methods (network segmentation using VLANs or SGTs Layer 2 and port security DHCP snooping Dynamic ARP inspection storm control and defenses against MAC, ARP, VLAN hopping, STP, and DHCP rogue attacks)
Answer Correct answer: C — A DHCP packet is dropped when received on an untrusted interface and the source MAC address does not match the DHCP client hardware address.

An engineer is configuring DHCP on a Cisco switch and wants to ensure that a DHCP packet will be dropped. Under which condition will this occur?

  1. A packet from a DHCP server is received from inside the network or firewall.
  2. All packets are dropped until the administrator manually enters the approved servers into the DHCP snooping database.
  3. A packet is received on an untrusted interface, and the source MAC address and the DHCP client hardware address do not match. Correct Answer
  4. A DHCP relay agent forwards a DHCP packet that includes a relay-agent IP address that is 0.0.0.0.

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The core concept is DHCP snooping security features, specifically the trap of confusing general DHCP behavior with specific anti-spoofing validation rules.

This question tests DHCP snooping configuration and packet validation logic on Cisco switches. It establishes that packets are dropped when source MAC and client hardware address mismatches occur on untrusted interfaces.

Candidates often select Option D because they misinterpret the role of a relay agent or confuse it with invalid IP scenarios, failing to recognize that Option C describes a definitive security violation caught by snooping.

Community Discussion (3 comments)

ITVI 👍 1 Selected: C
Okay this question makes no sense as I read it as a double negative. Why drop dhcp packets if you are making the switch a dhcp server? I think the question was that the engineer is configuring 'DHCP Snooping" so therefore the answer is C. But to answer the original question than yeah, the answer is D ... which then make sense lol.
dfb0b7d 👍 2
Packet Validation •The switch receives a packet on an untrusted interface, and the source MAC address and the DHCP client hardware address do not match. This check is performed only if the DHCP snooping MAC address verification option is turned on. •The switch receives a DHCPRELEASE or DHCPDECLINE message from an untrusted host with an entry in the DHCP snooping binding table, and the interface information in the binding table does not match the interface on which the message was received. •The switch receives a DHCP packet that includes a relay agent IP address that is not 0.0.0.0. C needs to have DHCP snooping configured which is not explicitly stated in the question. But in D probably the word "not" is missing, so either a typo or otherwise I'd still choose C. https://www.cisco.com/en/US/docs/general/Test/dwerblo/broken_guide/snoodhcp.html#wp1109594
devildog 👍 1 Selected: C
because of DHCP snooping, C. seems like the most logical answer

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Option C is correct because DHCP snooping includes a feature called 'MAC address verification'. When enabled, the switch compares the source MAC address in the Ethernet header with the Client Hardware Address (ciaddr) in the DHCP payload. If these do not match on an untrusted port, the packet is considered spoofed and is dropped.

Why the Other Options Are Wrong

Option A is incorrect; receiving a DHCP offer from inside the network is expected behavior if the server is trusted. Option B is incorrect because DHCP snooping does not drop all packets by default; it only drops unauthorized offers from untrusted ports unless the binding table is explicitly used for enforcement, but even then, it doesn't drop all packets indiscriminately. Option D is incorrect because a relay-agent IP of 0.0.0.0 is typically valid in certain initial discovery phases or specific relay configurations, not an automatic drop condition like a MAC mismatch.

Community Comment Notes

The community overwhelmingly agrees with Option C. One user noted that while the question phrasing might seem ambiguous ('ensuring a packet will be dropped'), Option C represents the most logical security trigger for DHCP snooping. Another commenter highlighted that without the context of 'DHCP Snooping', the question is confusing, but with that context, C is the clear technical answer for packet validation failure.

Exam Strategy

When answering DHCP snooping questions, always look for keywords like 'untrusted interface' and 'verification'. Remember that the primary purpose of snooping is to build a binding table and prevent rogue servers, with MAC verification being a key anti-spoofing mechanism.

Frequently Asked Questions

What triggers DHCP snooping to drop a packet based on MAC?

It triggers when the source MAC in the Ethernet frame differs from the Client Hardware Address in the DHCP payload on an untrusted port.

Does DHCP snooping block all DHCP traffic initially?

No, it only blocks DHCP offers/acks from untrusted ports. Other DHCP messages like Discover/Request are allowed to pass through.

Related Analysis

← Back to 350-701 Study Guide