Cisco CCNA (200-301)Security FundamentalsMedium
An administrator has enabled port security on interface GigabitEthernet0/5 with 'switchport port-security' and set the maximum to 1. The administrator wants the switch to dynamically learn the connected device's MAC address and automatically add it to the running configuration so it survives a reload if the config is saved. Which command accomplishes this?
- Aswitchport port-security violation shutdown
- Bswitchport port-security maximum 1
- Cswitchport port-security aging time 0
- Dswitchport port-security mac-address sticky
Show answer & explanationAnswer & explanation
Correct answer: D. switchport port-security mac-address sticky
The 'switchport port-security mac-address sticky' command tells the switch to dynamically learn the connected MAC address and convert it into a 'sticky secure' MAC address, which is added to the running configuration. If the configuration is then saved with 'copy running-config startup-config', the MAC address persists across reboots.
Why the other options are wrong
- A. This sets the violation action but does not enable dynamic learning of MAC addresses.
- B. This sets the maximum allowed MAC count but does not enable sticky learning.
- C. This relates to aging timers for secure addresses, not sticky learning.
Port Security Sticky MAC
The 'switchport port-security mac-address sticky' command causes a switch to dynamically learn a connected device's MAC address and add it to the running configuration as a secure MAC.
- Must save config to persist across reboot
- Learned addresses appear as 'sticky' in show port-security
- Reduces manual MAC configuration effort
Memory trick: Sticky MACs stick to the config once you save it.