Cisco CCNP Security · SCOR + SNCF · SCOR 350-701 v2.0 · 2.3 & 2.5 Infrastructure security

Infrastructure security: Layer 2 attacks and defences

The access layer is where most attacks start. Learn each Layer 2 attack — MAC flooding, rogue DHCP, ARP spoofing / MITM, VLAN hopping, STP takeover, storms and IP spoofing — then configure the port-security, DHCP snooping, Dynamic ARP Inspection, storm-control, BPDU/root guard and IP Source Guard that shut them down.

75 min read13 chapters5 labs15 quiz8 scenarios15 interview Q&A

This module is part of the paid plans

The free Starter plan opens the first module of every path. Upgrade to unlock this module's lesson, labs, quiz and scenarios.

Your free Starter plan includes

  • ✓First module of every path — lessons and quizzes
  • ✓3 hands-on labs in total
  • ✓Practice questions (up to 10 per set)
  • ✓Build your own lab — 3 sessions a month, up to 4 devices

Inside this module

  • Lab · MAC flooding vs port security
  • Lab · Rogue DHCP + ARP spoofing vs snooping and DAI
  • Lab · VLAN hopping and STP takeover defences
  • Lab · Storm-control and IP Source Guard
  • Lab · Hardening locked out the good guys
🎓 For educational purposes only — all devices are simulationsTerms of UsePrivacy Policy© 2026 Network Kings
CONFIG by Network Kings — an educational IT simulation platform for learning purposes only. It is not Cisco IOS, Junos, FortiOS or PAN-OS and contains no Cisco, Juniper, Fortinet or Palo Alto Networks software. Cisco, IOS, CCNA, CCNP, Juniper, JNCIA, JNCIS, JNCIP, Fortinet, FortiGate, FortiOS, NSE, Palo Alto Networks, PAN-OS and PCNSE are trademarks of their respective owners. Network Kings is not affiliated with or endorsed by Cisco Systems, Inc., Juniper Networks, Inc., Fortinet, Inc. or Palo Alto Networks, Inc.