ISC2 Certified in Cybersecurity (CC)Network SecurityMedium
A network administrator is configuring a new switch for a department that handles sensitive customer data. To prevent unauthorized devices from connecting to specific switch ports, the administrator enables a feature that binds specific MAC addresses to individual ports. What security feature is being implemented?
- APort Security
- BDHCP Snooping
- CPort Mirroring
- DVLAN Tagging
Show answer & explanationAnswer & explanation
Correct answer: A. Port Security
Port security is a switch feature that allows administrators to restrict input on a port by limiting and/or identifying the MAC addresses of the stations allowed to access the port. This prevents unauthorized devices from connecting.
Why the other options are wrong
- B. DHCP snooping prevents rogue DHCP servers and ensures valid IP address assignments, but it doesn't control device access by MAC address at the port level.
- C. Port mirroring copies traffic from one port to another for analysis and is not a security access control feature.
- D. VLAN tagging separates traffic into logical networks but doesn't prevent unauthorized devices from connecting to a port.
Port Security
A Layer 2 security feature on network switches that restricts input on an interface by limiting and/or identifying the MAC addresses of stations allowed to access the port.
- Binds specific MAC addresses to switch ports.
- Prevents unauthorized devices from connecting.
- Can be configured to shut down or restrict traffic from unauthorized MACs.
Memory trick: Port Security is like a bouncer checking IDs at each port's door.