PracticeLabs
Week 7Section quizRequired8 questions~10 min

Layer 2 Security & the Security Program

Covers Lesson 3 and Lesson 4

Checks that you can match each access-layer attack to its control, predict port-security behaviour from the defaults, and place the human layer alongside the technical one.

Topics covered

  • Attack-to-control pairings at the access layer
  • Port security defaults and violation modes
  • DHCP snooping trust and the binding table
  • DAI's dependency on snooping
  • BPDU Guard versus Root Guard
  • Awareness, training, and physical access

Every question here is answerable from the first-party notes of the lessons above. You commit to an answer before you see whether it was right.

This quiz is a Week 7 milestone in its own right. Passing it does not change the completion state of any individual lesson, and you do not need it to finish the lessons it covers.

Section quiz

Layer 2 Security & the Security Program

8 questions covering Lesson 3 and Lesson 4. Answer each one before you see whether you were right.

Question 1 of 8

1. You enable switchport port-security on an access port and change nothing else, then connect an IP phone with a PC behind it. What happens?
2. Which violation mode drops the offending frames but neither logs nor counts them?
3. How do you recover a port that port security has err-disabled?
4. In DHCP snooping, which ports should be marked trusted?
5. Why can Dynamic ARP Inspection not run usefully without DHCP snooping?
6. A Portfast access port with BPDU Guard receives a BPDU, and separately a downstream-facing port with Root Guard receives a superior BPDU. What happens in each case?
7. What distinguishes user awareness from training?
8. Why is physical access to a device's console port considered capable of defeating strong software hardening?