Implementing and Operating Cisco Enterprise Network Core Technologies (ENCOR) v1.2SecurityEasy

A network administrator is configuring a new switch to enhance network security. The administrator wants to prevent unauthorized devices from connecting to specific switch ports and ensure that only devices with known MAC addresses can access the network. Which security feature should be implemented on the switch ports to achieve this goal?

  1. AIP Source Guard
  2. BDHCP snooping
  3. CDynamic ARP Inspection (DAI)
  4. DPort Security
Show answer & explanation

Correct answer: D. Port Security

Port Security allows an administrator to restrict input to an interface by limiting and identifying MAC addresses of stations allowed to access the port. This directly addresses the requirement to prevent unauthorized devices and allow only known MAC addresses.

Why the other options are wrong

  • A. IP Source Guard prevents spoofing of IP and MAC addresses by filtering traffic based on binding entries.
  • B. DHCP snooping prevents rogue DHCP servers and ensures clients receive IP addresses from legitimate DHCP servers.
  • C. Dynamic ARP Inspection (DAI) prevents ARP spoofing attacks by validating ARP packets.

Port Security

A Layer 2 security feature on Cisco switches that restricts input to an interface by limiting and identifying MAC addresses of devices allowed to access the port.

  • Limits the number of MAC addresses allowed on a port.
  • Can specify static MAC addresses or dynamically learn them.
  • Configurable violation modes (shutdown, restrict, protect).
  • Helps prevent MAC address spoofing and unauthorized access.

Memory trick: Ports Guard MACs from Unknown Access

More Security questions