ISC2 Certified in Cybersecurity (CC)Network SecurityMedium

A network administrator is configuring a new switch for a department that handles sensitive customer data. To prevent unauthorized devices from connecting to specific switch ports, the administrator enables a feature that binds specific MAC addresses to individual ports. What security feature is being implemented?

  1. APort Security
  2. BDHCP Snooping
  3. CPort Mirroring
  4. DVLAN Tagging
Show answer & explanation

Correct answer: A. Port Security

Port security is a switch feature that allows administrators to restrict input on a port by limiting and/or identifying the MAC addresses of the stations allowed to access the port. This prevents unauthorized devices from connecting.

Why the other options are wrong

  • B. DHCP snooping prevents rogue DHCP servers and ensures valid IP address assignments, but it doesn't control device access by MAC address at the port level.
  • C. Port mirroring copies traffic from one port to another for analysis and is not a security access control feature.
  • D. VLAN tagging separates traffic into logical networks but doesn't prevent unauthorized devices from connecting to a port.

Port Security

A Layer 2 security feature on network switches that restricts input on an interface by limiting and/or identifying the MAC addresses of stations allowed to access the port.

  • Binds specific MAC addresses to switch ports.
  • Prevents unauthorized devices from connecting.
  • Can be configured to shut down or restrict traffic from unauthorized MACs.

Memory trick: Port Security is like a bouncer checking IDs at each port's door.

More Network Security questions