Cisco CCNA (200-301)Security FundamentalsMedium

An administrator has enabled port security on interface GigabitEthernet0/5 with 'switchport port-security' and set the maximum to 1. The administrator wants the switch to dynamically learn the connected device's MAC address and automatically add it to the running configuration so it survives a reload if the config is saved. Which command accomplishes this?

  1. Aswitchport port-security violation shutdown
  2. Bswitchport port-security maximum 1
  3. Cswitchport port-security aging time 0
  4. Dswitchport port-security mac-address sticky
Show answer & explanation

Correct answer: D. switchport port-security mac-address sticky

The 'switchport port-security mac-address sticky' command tells the switch to dynamically learn the connected MAC address and convert it into a 'sticky secure' MAC address, which is added to the running configuration. If the configuration is then saved with 'copy running-config startup-config', the MAC address persists across reboots.

Why the other options are wrong

  • A. This sets the violation action but does not enable dynamic learning of MAC addresses.
  • B. This sets the maximum allowed MAC count but does not enable sticky learning.
  • C. This relates to aging timers for secure addresses, not sticky learning.

Port Security Sticky MAC

The 'switchport port-security mac-address sticky' command causes a switch to dynamically learn a connected device's MAC address and add it to the running configuration as a secure MAC.

  • Must save config to persist across reboot
  • Learned addresses appear as 'sticky' in show port-security
  • Reduces manual MAC configuration effort

Memory trick: Sticky MACs stick to the config once you save it.

More Security Fundamentals questions