Valid H12-891_V1.0 Dumps shared by ExamDiscuss.com for Helping Passing H12-891_V1.0 Exam! ExamDiscuss.com now offer the newest H12-891_V1.0 exam dumps, the ExamDiscuss.com H12-891_V1.0 exam questions have been updated and answers have been corrected get the newest ExamDiscuss.com H12-891_V1.0 dumps with Test Engine here:
Man-in-the-middle attacks (MITM) or IP/MAC Spoofing attacks are common on intranets and can cause information leakage. Which configuration method can prevent these attacks?
Correct Answer: D
Comprehensive and Detailed Explanation: # The Best Protection Against MITM and Spoofing Attacks:# (D) Associating DHCP Snooping with IPSG (IP Source Guard) and DAI (Dynamic ARP Inspection) provides complete protection by: * Blocking rogue DHCP servers. * Preventing MAC/IP spoofing. * Ensuring only valid clients access the network. # Why Not Other Options?# (A) Configuring trusted/untrusted interfaces only helps block rogue DHCP servers, but does not prevent spoofing.# (B) Limiting MAC address learning prevents MAC flooding, but does not stop MITM attacks.# (C) Checking the CHADDR field in DHCP Snooping helps detect spoofed requests, but does not block all MITM scenarios. # Reference: Huawei HCIE Datacom - Security Mechanisms for Intranet Protection