DevNet Associate (DEVASC) v1.0Network FundamentalsMedium

A network engineer is configuring a new Layer 2 switch. To prevent unauthorized devices from connecting to a specific port and to automatically disable the port if a new MAC address is detected, which port security violation mode should be configured?

  1. Atrap
  2. Bprotect
  3. Cshutdown
  4. Drestrict
Show answer & explanation

Correct answer: C. shutdown

The 'shutdown' violation mode disables the port immediately upon detecting a violation and increments the violation counter. This requires manual intervention to re-enable the port, providing the strongest security measure as requested in the scenario.

Why the other options are wrong

  • A. 'trap' is not a violation mode itself; it's an action (sending an SNMP trap) that occurs in 'restrict' and 'shutdown' modes.
  • B. The 'protect' mode drops frames from unauthorized MAC addresses but does not log the violation or disable the port.
  • D. The 'restrict' mode drops frames, sends an SNMP trap, and increments a violation counter, but does not disable the port.

Port Security Violation Modes

Actions a switch takes when an unauthorized MAC address attempts to access a port configured with port security.

  • Protect: Drops frames, no notification.
  • Restrict: Drops frames, sends SNMP trap, increments counter.
  • Shutdown: Disables port, sends SNMP trap, increments counter, requires manual re-enable.

Memory trick: Protect, Restrict, Shutdown: Preventing Unwanted Access.

More Network Fundamentals questions