CompTIA Network+ (N10-009)Network SecurityMedium

A network administrator wants each switch access port to learn only one MAC address automatically and to disable the port if a second, unauthorized device is detected. Which configuration accomplishes this?

  1. ADynamic ARP inspection on the VLAN
  2. BDHCP snooping with a trusted uplink
  3. CPort security with sticky MAC learning and shutdown violation mode
  4. D802.1X with MAB fallback
Show answer & explanation

Correct answer: C. Port security with sticky MAC learning and shutdown violation mode

Port security with sticky learning dynamically records the first MAC address seen on a port and adds it to the running configuration; setting the violation mode to shutdown administratively disables the port if a second MAC address appears. DHCP snooping and DAI address different attack vectors (rogue DHCP servers and ARP spoofing).

Why the other options are wrong

  • A. DAI validates ARP packets against DHCP snooping bindings, not MAC counts.
  • B. DHCP snooping filters rogue DHCP servers, not MAC address limits.
  • D. 802.1X with MAB authenticates devices but doesn't inherently limit MAC count per port.

Port Security (Sticky MAC)

A switch feature that limits the number of MAC addresses allowed on a port and can dynamically learn and store them as 'sticky' entries.

  • Max MAC count can be set (e.g., 1)
  • Violation modes: protect, restrict, shutdown
  • Shutdown mode err-disables the port on violation

Memory trick: One port, one MAC—break the rule and the port goes dark.

More Network Security questions