CompTIA Network+ (N10-009)Network SecurityMedium
A network administrator wants each switch access port to learn only one MAC address automatically and to disable the port if a second, unauthorized device is detected. Which configuration accomplishes this?
- ADynamic ARP inspection on the VLAN
- BDHCP snooping with a trusted uplink
- CPort security with sticky MAC learning and shutdown violation mode
- D802.1X with MAB fallback
Show answer & explanationAnswer & explanation
Correct answer: C. Port security with sticky MAC learning and shutdown violation mode
Port security with sticky learning dynamically records the first MAC address seen on a port and adds it to the running configuration; setting the violation mode to shutdown administratively disables the port if a second MAC address appears. DHCP snooping and DAI address different attack vectors (rogue DHCP servers and ARP spoofing).
Why the other options are wrong
- A. DAI validates ARP packets against DHCP snooping bindings, not MAC counts.
- B. DHCP snooping filters rogue DHCP servers, not MAC address limits.
- D. 802.1X with MAB authenticates devices but doesn't inherently limit MAC count per port.
Port Security (Sticky MAC)
A switch feature that limits the number of MAC addresses allowed on a port and can dynamically learn and store them as 'sticky' entries.
- Max MAC count can be set (e.g., 1)
- Violation modes: protect, restrict, shutdown
- Shutdown mode err-disables the port on violation
Memory trick: One port, one MAC—break the rule and the port goes dark.