CompTIA Network+ (N10-009)Network ImplementationMedium

A network administrator configures port security on a switch access port, setting the maximum MAC address count to one and the violation action to shutdown. A user later connects a small unmanaged hub to that port and attaches two additional devices. What is the expected result?

  1. AThe switch automatically creates a new VLAN for the extra devices
  2. BThe switch silently drops frames from the extra MAC addresses only
  3. CThe port transitions to an err-disabled state
  4. DThe port forwards traffic from all connected devices normally
Show answer & explanation

Correct answer: C. The port transitions to an err-disabled state

When port security detects more MAC addresses than the configured maximum and the violation mode is set to shutdown, the switch immediately places the port into an err-disabled state, blocking all traffic until an administrator manually re-enables it.

Why the other options are wrong

  • A. Switches do not dynamically create VLANs in response to port security violations.
  • B. Silently dropping only extra MACs describes the 'restrict' or 'protect' violation modes, not shutdown.
  • D. This would only occur if the violation mode were set to protect, not shutdown.

Port Security Violation Modes

A switch security feature limiting the number of MAC addresses allowed on a port; violation actions include protect (drop silently), restrict (drop + log), and shutdown (err-disable the port).

  • Shutdown mode disables the port and requires manual/automatic re-enable
  • Protect mode drops excess traffic without logging
  • Restrict mode drops excess traffic and logs/counts violations

Memory trick: Shutdown mode = slam the door shut on violations.

More Network Implementation questions