2026 Securities Licensing Study Guides (SIE, Series 7 & Series 66) are now live
Domain 4 • Chapter 4Section 4.2

4.2 Layer 2 Hardening: Port Security, DHCP Snooping & Dynamic ARP Inspection

Explores switchport security violation modes (Protect, Restrict, Shutdown), DHCP Snooping trusted ports, and Dynamic ARP Inspection.

🎯 Key CompTIA Network+ Exam Takeaways

  • Port security violation modes: Protect drops frames silently; Restrict drops frames, increments counter, logs Syslog, and sends SNMP traps; Shutdown err-disables the port.
  • DHCP Snooping designates access ports as untrusted, dropping rogue DHCPOFFER and DHCPACK packets.
  • Dynamic ARP Inspection (DAI) inspects ARP packets on untrusted ports against the DHCP Snooping database to prevent ARP poisoning.

Access switches represent the front line of network defense. Switch Port Security limits the number of MAC addresses allowed on an interface, learning addresses dynamically ('sticky') and enforcing violation modes: Protect, Restrict, or Shutdown.

DHCP Snooping defends against rogue DHCP servers. Switch ports connected to clients are configured as 'untrusted'. The switch inspects DHCP traffic, dropping server messages on untrusted ports while compiling an IP-to-MAC binding database.

Dynamic ARP Inspection (DAI) leverages the DHCP Snooping table to validate ARP replies on untrusted ports, discarding invalid packets to eradicate ARP cache poisoning.

⚠️ Common Pearson VUE Exam Traps

  • Attempting to deploy Dynamic ARP Inspection without first enabling DHCP Snooping to populate the binding database.
  • Using Protect mode when audit compliance requires Syslog and SNMP alerts for port security violations.

Knowledge Checkpoint

Knowledge Checkpoint • Section 4.2

To prevent malicious actors from performing ARP poisoning attacks across an enterprise access switch, an administrator enables Dynamic ARP Inspection (DAI). What prerequisite security feature must be configured first to build the trusted database that DAI uses to validate ARP packets?