โ† All COMPTIA Flashcard Decks

Network+ Ethernet Switching Features Flashcards

7 cards from real COMPTIA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Network+ Ethernet Switching Features flashcards as text
  1. Which attack does Dynamic ARP Inspection (DAI) specifically mitigate?

    Answer: ARP poisoning/spoofing attacks

    DAI validates ARP packets against the DHCP snooping binding table to prevent attackers from sending gratuitous ARPs with forged MAC-to-IP mappings.

  2. What is the primary function of the Spanning Tree Protocol (STP) in an Ethernet network?

    Answer: Prevent Layer 2 loops while allowing redundant paths

    STP prevents Layer 2 broadcast storms and loops by selectively blocking redundant paths while keeping them available for failover.

  3. A VLAN hopping attack uses a double-tagged 802.1Q frame. What is the most effective mitigation?

    Answer: Change the native VLAN to an unused VLAN ID and do not assign it to any user ports

    Changing the native VLAN to an unused, dedicated VLAN prevents double-tagged frames from being forwarded onto victim VLANs.

  4. In Rapid Spanning Tree Protocol (RSTP 802.1w), which port role replaces the traditional STP designated port on non-root segments?

    Answer: Designated port

    RSTP retains the designated port role; each non-root LAN segment still has one designated port responsible for forwarding traffic toward the root.

  5. What does storm control on a switch port do when a traffic threshold is exceeded?

    Answer: Shuts down or rate-limits the port to suppress the traffic surge

    Storm control monitors broadcast, multicast, or unicast traffic rates and shuts down or rate-limits the port when a configured threshold is exceeded.

  6. Which VTP mode allows a switch to apply VLAN configuration received from a VTP server but prevents it from originating VTP advertisements?

    Answer: VTP client mode

    VTP client mode accepts and synchronizes VLAN information from VTP servers but cannot create, modify, or delete VLANs locally.

  7. A switch port connected to a host is placed in the err-disabled state. Which condition most likely caused this?

    Answer: BPDU guard detected a BPDU on a PortFast-enabled port

    BPDU guard places a PortFast-enabled port into err-disabled state upon receiving any BPDU, indicating an unauthorized switch connection.