Aruba Associate Routing & IP Services Flashcards
6 cards from real ACA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Aruba Associate Routing & IP Services flashcards as text
What is IPv6 and why was it developed?
Answer: The successor to IPv4 developed to address IPv4 address exhaustion with a 128-bit address space
IPv6 was developed to replace IPv4 due to IPv4 address exhaustion, using 128-bit addresses to provide an essentially unlimited pool of unique IP addresses.
Which IPv6 address type is only routable within the local network segment and always begins with fe80?
Answer: Link-Local (fe80::/10)
IPv6 Link-Local addresses (fe80::/10 prefix) are automatically assigned to interfaces and are only routable within the local link, not forwarded by routers.
What Aruba AOS-CX feature can act as a DHCP server to assign IP addresses to clients on directly connected VLANs?
Answer: DHCP Server Pool
Aruba AOS-CX switches can be configured with a DHCP Server Pool to act as a local DHCP server, assigning IP addresses to clients connected to local VLAN interfaces.
What is DHCP Snooping, and what does it protect against?
Answer: A security feature that validates DHCP messages; protects against rogue DHCP servers
DHCP Snooping validates DHCP messages on untrusted ports and blocks unauthorized DHCP server responses, protecting clients from receiving incorrect IP configuration from rogue servers.
Which ARP security feature on Aruba switches prevents ARP spoofing attacks by validating ARP packets against the DHCP Snooping binding table?
Answer: Dynamic ARP Inspection (DAI)
Dynamic ARP Inspection (DAI) validates ARP packets against the DHCP Snooping binding table, dropping ARP packets with invalid MAC-to-IP mappings to prevent ARP spoofing.
What is the purpose of IP Source Guard on an Aruba switch?
Answer: To validate that source IP addresses on untrusted ports match the DHCP Snooping binding table, preventing IP spoofing
IP Source Guard filters traffic on untrusted ports by verifying source IP addresses against the DHCP Snooping binding table, preventing hosts from spoofing IP addresses of other clients.