Implementing and Operating Cisco Enterprise Network Core Technologies (ENCOR) v1.2InfrastructureEasy
A network administrator is configuring a new Cisco Catalyst 9300 switch. The requirement is to ensure that only specific devices with known MAC addresses can connect to a particular port, and if an unknown device attempts to connect, the port should shut down immediately. Which feature should the administrator configure?
- APort security
- BDHCP snooping
- CDynamic ARP Inspection (DAI)
- D802.1X authentication
Show answer & explanationAnswer & explanation
Correct answer: A. Port security
Port security allows an administrator to restrict input to an interface by limiting and identifying MAC addresses of stations allowed to access the port. It can be configured to shut down the port if a violation occurs.
Why the other options are wrong
- B. DHCP snooping prevents rogue DHCP servers and malicious DHCP messages.
- C. DAI prevents ARP spoofing attacks by validating ARP packets.
- D. 802.1X provides port-based network access control, often with user authentication, not strictly MAC address restriction.
Port Security
A Layer 2 security feature on Cisco switches that restricts input to an interface by limiting and identifying MAC addresses of stations allowed to access the port.
- Limits the number of MAC addresses learned on a port.
- Can be configured to shut down the port, restrict traffic, or protect traffic upon violation.
- Supports static, dynamic, and sticky MAC address configurations.
Memory trick: Secure Your Port, Lock Down MACs!