ISC2 CISSP (Certified Information Systems Security Professional)Communication and Network SecurityMedium

A security engineer is configuring a network device to prevent MAC address spoofing and limit the number of MAC addresses that can be learned on a specific port. This measure is intended to mitigate attacks that involve flooding the switch's MAC address table. Which network security component feature is being configured?

  1. A802.1X Port-Based Authentication
  2. BDHCP Snooping
  3. CPort Security
  4. DARP Inspection
Show answer & explanation

Correct answer: C. Port Security

Port security is a switch feature that allows administrators to define which MAC addresses are allowed on a specific port, limit the number of MAC addresses, and take action (e.g., shutdown) if violations occur. This directly mitigates MAC address spoofing and MAC table flooding.

Why the other options are wrong

  • A. 802.1X provides authentication for devices connecting to a port but does not directly prevent MAC spoofing or limit MAC addresses learned on a port after authentication.
  • B. DHCP snooping prevents rogue DHCP servers and ensures valid IP assignments but does not directly address MAC address spoofing or MAC table flooding.
  • D. ARP inspection validates ARP packets to prevent ARP spoofing but does not prevent MAC address spoofing or MAC table flooding, which are Layer 2 issues directly related to the switch's MAC table.

Port Security

A switch feature that restricts input to an interface by limiting and identifying MAC addresses of stations allowed to access the port.

  • Prevents MAC address spoofing and MAC flooding attacks.
  • Allows static configuration of MAC addresses or dynamic learning up to a limit.
  • Can be configured to shut down the port, restrict traffic, or protect against violations.

Memory trick: Port Security 'Locks' the 'Port' by 'MAC' address.

More Communication and Network Security questions