ISC2 CISSP (Certified Information Systems Security Professional)Communication and Network SecurityEasy

A security engineer is configuring a network device to prevent MAC address spoofing and limit the number of devices that can connect to a specific switch port. The goal is to bind specific MAC addresses to specific ports or to restrict the total number of learned MAC addresses on a port to a predefined limit. Which feature should the engineer enable on the switch port to achieve this?

  1. APort Security
  2. BVirtual Local Area Network (VLAN)
  3. CSpanning Tree Protocol (STP)
  4. D802.1X Port-Based Authentication
Show answer & explanation

Correct answer: A. Port Security

Port Security is a Layer 2 switch feature that allows administrators to control which MAC addresses are allowed to send traffic through a specific port. It can be configured to allow only specific MAC addresses, or to limit the number of MAC addresses learned on a port, preventing MAC spoofing and unauthorized device connections.

Why the other options are wrong

  • B. VLANs segment a network logically but do not inherently prevent MAC spoofing on a given port.
  • C. STP prevents network loops but has no function related to MAC address security or limiting devices per port.
  • D. 802.1X provides authentication for network access but doesn't directly bind MAC addresses or limit learned MACs on a port.

Port Security

A Layer 2 switch feature that allows an administrator to restrict input to a port by limiting and/or identifying MAC addresses of the devices allowed to connect to the port.

  • Prevents MAC address spoofing.
  • Controls the number of MAC addresses learned on a port.
  • Can be configured to statically bind MACs or dynamically learn them up to a limit.
  • Commonly used to enhance physical security on network access ports.

Memory trick: Port Security Protects Physical Plugs.

More Communication and Network Security questions