How can VLAN-hopping attacks be mitigated?
Choose an answer
Tap an option to check your answer.
Correct answer: manually implement trunk ports and disable DTP.
Why this is the answer
Manually implementing trunk ports and disabling Dynamic Trunking Protocol (DTP) is the most effective mitigation. DTP, if left enabled, can allow an attacker to negotiate a trunk link from an access port, enabling them to send traffic tagged for different VLANs (VLAN hopping). By manually configuring trunk ports and explicitly setting access ports, you prevent unauthorized trunking. Configuring extended VLANs (VLANs 1006-4094) does not prevent VLAN hopping. Activating all ports and placing them in the default VLAN (VLAN 1) actually increases the attack surface by making more ports accessible and consolidating traffic, making VLAN hopping easier. Enabling Dynamic ARP Inspection (DAI) helps prevent ARP spoofing, but it does not directly mitigate VLAN-hopping attacks.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed