DevNet Associate (DEVASC) v1.0Network FundamentalsHard
A network technician is configuring port security on a Cisco Catalyst switch. The technician wants to ensure that if an unauthorized MAC address attempts to access a port, the port immediately shuts down and sends an SNMP trap. Which port security violation mode should be configured?
- ARestrict
- BStatic
- CShutdown
- DProtect
Show answer & explanationAnswer & explanation
Correct answer: C. Shutdown
The 'shutdown' violation mode immediately disables the interface and sends an SNMP trap when a security violation occurs. The interface remains in an error-disabled state until manually re-enabled or configured with an error recovery timeout.
Why the other options are wrong
- A. 'Restrict' drops packets from unauthorized MAC addresses, sends an SNMP trap, and increments a violation counter but does not shut down the port.
- B. Static is a method of configuring secure MAC addresses, not a violation mode.
- D. 'Protect' drops packets from unauthorized MAC addresses but does not log or send traps.
Port Security Violation Modes
Port security violation modes define the action a switch takes when an unauthorized MAC address is detected on a secure port.
- Shutdown: Disables port, sends trap.
- Restrict: Drops traffic, sends trap, increments counter.
- Protect: Drops traffic silently.
Memory trick: Port Security: 'Secure your Door, Pick your Penalty'