DevNet Associate (DEVASC) v1.0Network FundamentalsMedium
A network engineer is configuring a new Layer 2 switch. To prevent unauthorized devices from connecting to a specific port and to automatically disable the port if a new MAC address is detected, which port security violation mode should be configured?
- Atrap
- Bprotect
- Cshutdown
- Drestrict
Show answer & explanationAnswer & explanation
Correct answer: C. shutdown
The 'shutdown' violation mode disables the port immediately upon detecting a violation and increments the violation counter. This requires manual intervention to re-enable the port, providing the strongest security measure as requested in the scenario.
Why the other options are wrong
- A. 'trap' is not a violation mode itself; it's an action (sending an SNMP trap) that occurs in 'restrict' and 'shutdown' modes.
- B. The 'protect' mode drops frames from unauthorized MAC addresses but does not log the violation or disable the port.
- D. The 'restrict' mode drops frames, sends an SNMP trap, and increments a violation counter, but does not disable the port.
Port Security Violation Modes
Actions a switch takes when an unauthorized MAC address attempts to access a port configured with port security.
- Protect: Drops frames, no notification.
- Restrict: Drops frames, sends SNMP trap, increments counter.
- Shutdown: Disables port, sends SNMP trap, increments counter, requires manual re-enable.
Memory trick: Protect, Restrict, Shutdown: Preventing Unwanted Access.