ISC2 CISSP (Certified Information Systems Security Professional)Communication and Network SecurityMedium

A security engineer is tasked with securing network access for devices connecting to a corporate switch port. The requirement is to ensure that only authorized devices, identified by their MAC addresses, can connect to specific ports, and to limit the number of MAC addresses allowed per port to prevent unauthorized devices from connecting. What feature of a network switch should the engineer configure?

  1. APort Security
  2. BPort Mirroring
  3. CVLAN Tagging
  4. DSpanning Tree Protocol (STP)
Show answer & explanation

Correct answer: A. Port Security

Port Security is a switch feature that allows administrators to control which devices can connect to specific switch ports based on their MAC addresses. It can also limit the number of MAC addresses learned on a port, preventing MAC flooding and unauthorized device attachment.

Why the other options are wrong

  • B. Port Mirroring (or SPAN) copies traffic from one port to another for monitoring, not for access control.
  • C. VLAN tagging logically segments a network, but it doesn't control which specific MAC addresses can connect to a port.
  • D. Spanning Tree Protocol (STP) prevents network loops, it is not an access control mechanism for devices.

Port Security

A Layer 2 security feature on network switches that restricts input to an interface by limiting and identifying MAC addresses of stations allowed to access the port.

  • Prevents unauthorized devices from connecting.
  • Can limit the number of MAC addresses per port.
  • Actions can include shutdown, restrict, or protect when violations occur.

Memory trick: 'Port Security' locks down the port like a bouncer at a club.

More Communication and Network Security questions