5.0 Security Fundamentals
DHCP Snooping Practice Questions
Trusted/untrusted ports and rogue DHCP server mitigation.
Author-reviewed by LabFabric · 7 September 2026 · Report a content issue
One solved question, so you can see how these are marked
A switch has DHCP snooping globally enabled but no ports are trusted yet. What happens to DHCP server-side messages, such as DHCPOFFER, arriving on an access port?
They are dropped, because only trusted ports are allowed to forward DHCP server replies
DHCP snooping treats every port as untrusted by default once enabled, and untrusted ports are not permitted to send server-originated messages like DHCPOFFER or DHCPACK, which blocks rogue DHCP servers from responding to clients.
Every question in the set below is marked like this. The answers stay hidden until you pick one.
Find related practice in the CCNA path