Cisco CCNA (200-301)Security FundamentalsMedium

An administrator configures the following on interface FastEthernet0/3: switchport port-security switchport port-security maximum 3 switchport port-security mac-address sticky The port currently has one manually configured static MAC address and has already dynamically learned two more via sticky learning. A fourth unknown device now sends traffic on this port. Assuming the default violation mode, what occurs?

  1. AThe port shuts down and enters err-disabled state
  2. BThe switch adds the fourth MAC address and removes the oldest one automatically
  3. CThe switch drops only the fourth device's frames and continues forwarding for the other three
  4. DThe port continues learning MAC addresses until the interface is manually shut down
Show answer & explanation

Correct answer: A. The port shuts down and enters err-disabled state

The default port security violation mode is 'shutdown'. Since the maximum of 3 secure MAC addresses is already reached, any traffic from a 4th unknown MAC address triggers a security violation, and the default action puts the port into err-disabled state.

Why the other options are wrong

  • B. Port security does not auto-replace old addresses; that's not how the maximum limit works.
  • C. Only 'restrict' mode drops unauthorized frames while keeping the port up; that's not default.
  • D. The maximum has already been reached, so no further learning occurs.

Port Security Maximum & Default Violation

Port security limits the number of secure MAC addresses per port; exceeding the maximum triggers a violation action, defaulting to 'shutdown' which err-disables the port.

  • Default violation mode = shutdown
  • 'restrict' drops frames and logs, port stays up
  • 'protect' drops frames silently, no logging

Memory trick: Default mode SHUTS the door when the max is exceeded.

More Security Fundamentals questions