What practice helps protect a network from VLAN-hopping attacks?
Choose an answer
Tap an option to check your answer.
Correct answer: Assign all access ports to VLANs other than the native VLAN.
Why this is the answer
Assigning all access ports to VLANs other than the native VLAN is a key practice to prevent VLAN-hopping attacks, specifically those using the DTP (Dynamic Trunking Protocol) or double-tagging methods. By moving access ports off the native VLAN, an attacker cannot easily leverage the default untagged traffic behavior of the native VLAN to inject frames into other VLANs. Implementing port security is good for preventing unauthorized devices but doesn't directly stop VLAN hopping. Enabling dynamic ARP inspection protects against ARP spoofing, not VLAN hopping. Configuring an ACL to prevent traffic from changing VLANs is not a standard or effective mechanism for preventing VLAN hopping, as the attack often bypasses Layer 3 controls by manipulating Layer 2 frames.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed