300-101 Question 26
Which type of traffic does DHCP snooping drop?
A. discover messages
B. DHCP messages where the source MAC and client MAC do not match
C. traffic from a trusted DHCP server to client
D. traffic from a trusted DHCP server to client
D. DHCP messages where the destination MAC and client MAC do not match
Correct Answer: B
Explanation:
The switch validates DHCP packets received on the untrusted interfaces of VLANs with DHCP snooping enabled. The switch forwards the DHCP packet unless any of the following conditions occur (in which case the packet is dropped):The switch receives a packet (such as a DHCPOFFER,DHCPACK, DHCPNAK, or DHCPLEASEQUERY packet) from a DHCP server outside the network or firewall.
The switch receives a packet on an untrusted interface,and the source MAC address and the DHCP client hardware address do not match.This check is performed only if the DHCP snooping MAC address verification option is turned on.The switch receives a DHCPRELEASE or DHCPDE CLINE message from an untrusted host with an entry in the DHCP snooping binding table, and the interface information in the binding table does not match the interface on which the message was received. The switch receives a DHCP packet that includes a relay agent IP address that is not 0.0.0.0. To support trusted edge switches that are connected to untrusted aggregation-switch ports, you can enable the DHCP option-82 on untrusted port feature, which enables untrusted aggregation- switch ports to accept DHCP packets that include option-82 information. Configure the port on the edge switch that connects to the aggregation switch as a trusted port.Reference:http://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst6500/ios/12- 2SX/configuration/guide/book/snoodhcp.html
I have passed my 300-101 exam a few months ago and I obtained very good marks in my free 300-101 exam and also very glad that I get the right study material from the best firm. All the questions in the material was accurate and 100% real and valid. So, if you are willing to get free 300-101 dumps then visit Dumps4download.co.in and pass your exam in easy and best way.
ReplyDeleteFriends I pass my cisco 300-101 exam. And according to my opinion Pass4surekey is best because I prepared from there. For the relevant and latest Cisco 300-101dumps visit Pass4surekey. Pass4surekey will provide you the 300-101new questions which will be asked from you in the 300-101real exam. So, as far as my concern Pass4surekey is best for you if you want to pass 300-101in just first attempt with good grades. Here is an opportunity for you to buy Cisco 300-101pdf dumps with 100% guaranteed success. For more detail you can visit:
ReplyDeletehttps://www.pass4surekey.com/exam/300-101.html
Some important questions that you must prepared before exam:
QUESTION 1
A network engineer notices that transmission rates of senders of TCP traffic sharply increase and decrease simultaneously during periods of congestion. Which condition causes this?
A. global synchronization
B. tail drop
C. random early detection
D. queue management algorithm
Correct Answer: A
QUESTION 2
Which three problems result from application mixing of UDP and TCP streams within a network with no QoS? (Choose three.)
A. starvation
B. jitter
C. latency
D. windowing
E. lower throughput
Correct Answer: ACE
QUESTION 3
Which method allows IPv4 and IPv6 to work together without requiring both to be used for a single connection during the migration process?
A. dual-stack method
B. 6to4 tunneling
C. GRE tunneling
D. NAT-PT
Correct Answer: A
QUESTION 4
A network administrator executes the command clear ip route. Which two tables does this command clear and rebuild? (Choose two.)
A. IP routing
B. FIB
C. ARP cache
D. MAC address table
E. Cisco Express Forwarding table
F. topology table
Correct Answer: AB
QUESTION 5
Which two actions must you perform to enable and use window scaling on a router? (Choose two.)
A. Execute the command ip tcp window-size 65536.
B. Set window scaling to be used on the remote host.
C. Execute the command ip tcp queuemax.
D. Set TCP options to "enabled" on the remote host.
E. Execute the command ip tcp adjust-mss.
Correct Answer: AB