Implementing and Operating Cisco Enterprise Network Core Technologies (ENCOR) v1.2InfrastructureMedium
A network security engineer is implementing a new policy to prevent unauthorized devices from connecting to the corporate network via switch ports. The policy states that only devices with specific MAC addresses should be allowed to transmit traffic on certain access ports. Any device attempting to connect with an unapproved MAC address should trigger an alert and shut down the port. Which Layer 2 security feature should the engineer configure?
- ADHCP Snooping
- BDynamic ARP Inspection (DAI)
- CMAC Address Table Aging
- DPort Security
Show answer & explanationAnswer & explanation
Correct answer: D. Port Security
Port Security allows an administrator to restrict input access to a port based on MAC addresses. It can be configured to allow only specific MAC addresses, learn them dynamically, or enforce a maximum number of MAC addresses. When a violation occurs, it can shut down the port, restrict traffic, or protect it.
Why the other options are wrong
- A. DHCP Snooping prevents unauthorized DHCP servers and malicious DHCP messages, not unauthorized device access based on MAC.
- B. DAI prevents ARP spoofing attacks by validating ARP packets, not by restricting access based on MAC addresses.
- C. MAC Address Table Aging controls how long MAC addresses remain in the MAC address table before being refreshed, unrelated to port access control.
Port Security
A Layer 2 security feature on Cisco switches that restricts input to an interface by limiting and identifying MAC addresses of devices allowed to access the port.
- Controls access based on MAC addresses.
- Can be configured with static, dynamic, or sticky MACs.
- Violation modes include shutdown, restrict, protect.
Memory trick: Port Security is the bouncer at the club, only letting approved MACs in.