StudyToCert

All certifications / CCNA / Lessons

Cisco CCNA 200-301 v2.0 · Domain 4: Network services & security

Layer 2 security: port security (maximum, sticky, violation modes), DHCP snooping, dynamic ARP inspection

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

Many attacks on a LAN happen at Layer 2, from a device plugged into an access port: flooding the switch's MAC (media access control) address table, running a rogue DHCP (Dynamic Host Configuration Protocol) server, or poisoning ARP (Address Resolution Protocol) caches to intercept traffic. Cisco switches offer three features that work together to detect and prevent these attacks at the edge. The CCNA tests how each works, its defaults, and how they depend on one another.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study CCNA for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the CCNA study plan