Cisco Certified Support Technician (CCST) CybersecurityNetwork SecurityEasy

A network administrator is configuring a new switch and wants to prevent unauthorized devices from connecting to specific switch ports. The administrator needs a solution that will only allow devices with known MAC addresses to connect, and if an unknown MAC address attempts to connect, the port should shut down. Which security feature should the administrator implement?

  1. APort Security
  2. BBPDU Guard
  3. CDHCP Snooping
  4. DARP Inspection
Show answer & explanation

Correct answer: A. Port Security

Port Security is precisely designed to control which devices can connect to a switch port based on their MAC addresses. It can be configured to shut down a port upon detecting an unauthorized MAC address, fulfilling the administrator's requirement.

Why the other options are wrong

  • B. BPDU Guard protects the spanning-tree topology, not against unauthorized device connections.
  • C. DHCP Snooping prevents rogue DHCP servers, not unauthorized devices based on MAC address.
  • D. ARP Inspection prevents ARP spoofing, not unauthorized device connection based on MAC.

Port Security

Port Security is a Cisco switch feature that restricts input to a switch port by limiting and identifying MAC addresses of stations allowed to access the port.

  • Restricts MAC addresses on a port
  • Can be configured to shut down or restrict traffic
  • Prevents unauthorized device connections

Memory trick: Lock down the port like a bouncer at a club.

More Network Security questions