Network+ Ethernet Switching Features Flashcards
7 cards from real COMPTIA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Network+ Ethernet Switching Features flashcards as text
Which attack does Dynamic ARP Inspection (DAI) specifically mitigate?
Answer: ARP poisoning/spoofing attacks
DAI validates ARP packets against the DHCP snooping binding table to prevent attackers from sending gratuitous ARPs with forged MAC-to-IP mappings.
What is the primary function of the Spanning Tree Protocol (STP) in an Ethernet network?
Answer: Prevent Layer 2 loops while allowing redundant paths
STP prevents Layer 2 broadcast storms and loops by selectively blocking redundant paths while keeping them available for failover.
A VLAN hopping attack uses a double-tagged 802.1Q frame. What is the most effective mitigation?
Answer: Change the native VLAN to an unused VLAN ID and do not assign it to any user ports
Changing the native VLAN to an unused, dedicated VLAN prevents double-tagged frames from being forwarded onto victim VLANs.
In Rapid Spanning Tree Protocol (RSTP 802.1w), which port role replaces the traditional STP designated port on non-root segments?
Answer: Designated port
RSTP retains the designated port role; each non-root LAN segment still has one designated port responsible for forwarding traffic toward the root.
What does storm control on a switch port do when a traffic threshold is exceeded?
Answer: Shuts down or rate-limits the port to suppress the traffic surge
Storm control monitors broadcast, multicast, or unicast traffic rates and shuts down or rate-limits the port when a configured threshold is exceeded.
Which VTP mode allows a switch to apply VLAN configuration received from a VTP server but prevents it from originating VTP advertisements?
Answer: VTP client mode
VTP client mode accepts and synchronizes VLAN information from VTP servers but cannot create, modify, or delete VLANs locally.
A switch port connected to a host is placed in the err-disabled state. Which condition most likely caused this?
Answer: BPDU guard detected a BPDU on a PortFast-enabled port
BPDU guard places a PortFast-enabled port into err-disabled state upon receiving any BPDU, indicating an unauthorized switch connection.