Cisco CCNA (200-301)Security FundamentalsMedium
A switch port is configured with 'switchport port-security violation restrict' and a maximum of 2 MAC addresses. A third unauthorized device sends traffic on the port. What is the result?
- AThe frame from the unauthorized device is dropped, a syslog message is generated, and the violation counter increments, but the port stays up
- BThe port is immediately placed into err-disabled state
- CThe switch adds the new MAC address and removes the oldest learned address
- DThe frame is silently dropped with no logging and no counter increment
Show answer & explanationAnswer & explanation
Correct answer: A. The frame from the unauthorized device is dropped, a syslog message is generated, and the violation counter increments, but the port stays up
The 'restrict' violation mode drops traffic from unauthorized MAC addresses, increments the security violation counter, and generates a log/SNMP trap, but unlike 'shutdown' mode it does not disable the port.
Why the other options are wrong
- B. That describes the default 'shutdown' violation mode, not 'restrict'.
- C. Port security does not automatically replace learned MAC addresses this way.
- D. That describes 'protect' mode, which drops silently without logging.
Port Security Violation Modes
Determines the switch action when the number of allowed MAC addresses on a port is exceeded.
- shutdown: err-disables the port (default)
- restrict: drops frames, logs, increments counter, port stays up
- protect: drops frames silently, no logging
Memory trick: Shutdown Shouts, Restrict Records, Protect is Private