ISC2 CISSP (Certified Information Systems Security Professional)Communication and Network SecurityEasy
A security engineer is configuring a network device to prevent MAC address spoofing and limit the number of devices that can connect to a specific switch port. The goal is to bind specific MAC addresses to specific ports or to restrict the total number of learned MAC addresses on a port to a predefined limit. Which feature should the engineer enable on the switch port to achieve this?
- APort Security
- BVirtual Local Area Network (VLAN)
- CSpanning Tree Protocol (STP)
- D802.1X Port-Based Authentication
Show answer & explanationAnswer & explanation
Correct answer: A. Port Security
Port Security is a Layer 2 switch feature that allows administrators to control which MAC addresses are allowed to send traffic through a specific port. It can be configured to allow only specific MAC addresses, or to limit the number of MAC addresses learned on a port, preventing MAC spoofing and unauthorized device connections.
Why the other options are wrong
- B. VLANs segment a network logically but do not inherently prevent MAC spoofing on a given port.
- C. STP prevents network loops but has no function related to MAC address security or limiting devices per port.
- D. 802.1X provides authentication for network access but doesn't directly bind MAC addresses or limit learned MACs on a port.
Port Security
A Layer 2 switch feature that allows an administrator to restrict input to a port by limiting and/or identifying MAC addresses of the devices allowed to connect to the port.
- Prevents MAC address spoofing.
- Controls the number of MAC addresses learned on a port.
- Can be configured to statically bind MACs or dynamically learn them up to a limit.
- Commonly used to enhance physical security on network access ports.
Memory trick: Port Security Protects Physical Plugs.