Cisco Certified Support Technician (CCST) NetworkingSecurity FundamentalsHard

A network administrator is implementing a security measure to prevent unauthorized devices from connecting to the wired network by ensuring that only devices with specific, pre-approved hardware addresses are allowed. Which network security technology is being utilized?

  1. AAccess Control List (ACL)
  2. BPort security
  3. C802.1X authentication
  4. DMAC address filtering
Show answer & explanation

Correct answer: D. MAC address filtering

MAC address filtering (or MAC whitelisting) is the specific technology that allows or denies network access based on the unique MAC (Media Access Control) address of a network interface card. This directly addresses the requirement of allowing 'only devices with specific, pre-approved hardware addresses'. Port security can incorporate MAC address filtering, but MAC filtering itself is the core mechanism described.

Why the other options are wrong

  • A. ACLs filter traffic based on IP addresses, ports, and protocols, but not typically on the hardware MAC address for initial network access control at the physical layer.
  • B. Port security is a broader switch feature that can prevent MAC flooding, limit the number of MAC addresses per port, and can include MAC address filtering, but the core mechanism described is MAC filtering.
  • C. 802.1X authentication is a port-based network access control that uses a RADIUS server for stronger, more dynamic authentication, beyond just MAC addresses.

MAC Address Filtering

A security feature that controls access to a network based on the unique Media Access Control (MAC) address of a device's network interface card.

  • Uses a whitelist or blacklist of MAC addresses
  • Operates at Layer 2 (Data Link Layer)
  • Provides basic network access control
  • Can be bypassed by MAC spoofing

Memory trick: NAC 'N'arrowly 'A'llows 'C'onnections.

More Security Fundamentals questions