Implementing and Operating Cisco Enterprise Network Core Technologies (ENCOR) v1.2SecurityEasy

A network administrator is configuring a new Cisco switch and wants to ensure that only authorized devices can connect to specific switch ports. The goal is to prevent unauthorized devices from gaining network access by spoofing MAC addresses, even if they are known. Which feature should be implemented to achieve this, specifically tying a device's MAC address to its first learned port and preventing it from being used on other ports?

  1. ADynamic ARP Inspection (DAI)
  2. BDHCP snooping
  3. CMAC address security
  4. D802.1X authentication
Show answer & explanation

Correct answer: C. MAC address security

MAC address security, often referred to as port security, allows an administrator to restrict input to an interface by limiting and identifying MAC addresses of devices that are allowed to access the port. This prevents MAC address spoofing by unauthorized devices on other ports.

Why the other options are wrong

  • A. DAI inspects ARP packets to prevent ARP poisoning attacks but does not prevent a device from spoofing a MAC address on a different port.
  • B. DHCP snooping prevents rogue DHCP servers and ensures valid IP address assignments but doesn't specifically prevent MAC spoofing for network access.
  • D. 802.1X provides port-based network access control but relies on a separate authentication server and doesn't directly prevent MAC spoofing on other ports once authenticated.

MAC Address Security (Port Security)

A switch feature that restricts input to an interface by limiting and identifying the MAC addresses of devices allowed to access the port, preventing unauthorized MAC address spoofing.

  • Binds MAC addresses to specific switch ports.
  • Can be configured to statically or dynamically learn MAC addresses.
  • Offers various violation modes (shutdown, restrict, protect) when an unauthorized MAC is detected.

Memory trick: MACs stick to their own ports, no sharing allowed!

More Security questions