Cisco Certified Support Technician (CCST) NetworkingSecurity FundamentalsHard
A network administrator is implementing a security measure to prevent unauthorized devices from connecting to the wired network by ensuring that only devices with specific, pre-approved hardware addresses are allowed. Which network security technology is being utilized?
- AAccess Control List (ACL)
- BPort security
- C802.1X authentication
- DMAC address filtering
Show answer & explanationAnswer & explanation
Correct answer: D. MAC address filtering
MAC address filtering (or MAC whitelisting) is the specific technology that allows or denies network access based on the unique MAC (Media Access Control) address of a network interface card. This directly addresses the requirement of allowing 'only devices with specific, pre-approved hardware addresses'. Port security can incorporate MAC address filtering, but MAC filtering itself is the core mechanism described.
Why the other options are wrong
- A. ACLs filter traffic based on IP addresses, ports, and protocols, but not typically on the hardware MAC address for initial network access control at the physical layer.
- B. Port security is a broader switch feature that can prevent MAC flooding, limit the number of MAC addresses per port, and can include MAC address filtering, but the core mechanism described is MAC filtering.
- C. 802.1X authentication is a port-based network access control that uses a RADIUS server for stronger, more dynamic authentication, beyond just MAC addresses.
MAC Address Filtering
A security feature that controls access to a network based on the unique Media Access Control (MAC) address of a device's network interface card.
- Uses a whitelist or blacklist of MAC addresses
- Operates at Layer 2 (Data Link Layer)
- Provides basic network access control
- Can be bypassed by MAC spoofing
Memory trick: NAC 'N'arrowly 'A'llows 'C'onnections.