Cisco CCNA (200-301)Security FundamentalsMedium
An administrator configures the following on interface FastEthernet0/3: switchport port-security switchport port-security maximum 3 switchport port-security mac-address sticky The port currently has one manually configured static MAC address and has already dynamically learned two more via sticky learning. A fourth unknown device now sends traffic on this port. Assuming the default violation mode, what occurs?
- AThe port shuts down and enters err-disabled state
- BThe switch adds the fourth MAC address and removes the oldest one automatically
- CThe switch drops only the fourth device's frames and continues forwarding for the other three
- DThe port continues learning MAC addresses until the interface is manually shut down
Show answer & explanationAnswer & explanation
Correct answer: A. The port shuts down and enters err-disabled state
The default port security violation mode is 'shutdown'. Since the maximum of 3 secure MAC addresses is already reached, any traffic from a 4th unknown MAC address triggers a security violation, and the default action puts the port into err-disabled state.
Why the other options are wrong
- B. Port security does not auto-replace old addresses; that's not how the maximum limit works.
- C. Only 'restrict' mode drops unauthorized frames while keeping the port up; that's not default.
- D. The maximum has already been reached, so no further learning occurs.
Port Security Maximum & Default Violation
Port security limits the number of secure MAC addresses per port; exceeding the maximum triggers a violation action, defaulting to 'shutdown' which err-disables the port.
- Default violation mode = shutdown
- 'restrict' drops frames and logs, port stays up
- 'protect' drops frames silently, no logging
Memory trick: Default mode SHUTS the door when the max is exceeded.