Cisco Certified Support Technician (CCST) CybersecurityNetwork SecurityMedium

A network security engineer is configuring a new network segment for highly sensitive financial data. The requirement is to ensure that only specific, known devices with pre-approved MAC addresses can connect to this segment. Any unknown device attempting to connect must be automatically blocked. Which switch feature should be configured to enforce this policy?

  1. AVLAN Tagging
  2. BPort Mirroring
  3. CSpanning Tree Protocol (STP)
  4. DPort Security
Show answer & explanation

Correct answer: D. Port Security

Port Security allows a network administrator to configure a switch port to allow access only to devices with specified MAC addresses. If an unauthorized MAC address attempts to connect, the port can be configured to shut down or restrict traffic, effectively blocking unknown devices.

Why the other options are wrong

  • A. VLAN tagging segments networks logically but doesn't restrict access based on MAC addresses.
  • B. Port mirroring copies traffic to another port for monitoring, not for access control.
  • C. STP prevents network loops but has no role in MAC address-based access control.

Port Security

A switch feature that allows administrators to restrict the number of MAC addresses that can connect to a specific switch port and define actions for unauthorized MAC addresses.

  • Restricts access based on MAC addresses.
  • Prevents unauthorized devices from connecting to a port.
  • Can be configured to shut down a port or restrict traffic upon violation.
  • Improves Layer 2 security.

Memory trick: Port Security: Your switch's bouncer for MAC addresses.

More Network Security questions