Cisco Certified Support Technician (CCST) NetworkingNetwork AccessHard
A network administrator needs to ensure that only authorized devices can connect to specific switch ports in a highly secure environment. The solution should prevent rogue devices from gaining network access by learning MAC addresses and optionally applying an action if a violation occurs. Which feature should the administrator configure?
- AACL (Access Control Lists)
- BPort Security
- C802.1X Authentication
- DDHCP Snooping
Show answer & explanationAnswer & explanation
Correct answer: B. Port Security
Port Security allows an administrator to restrict input to an interface by limiting and identifying MAC addresses of devices allowed to access the port. It can be configured to learn MAC addresses dynamically, statically, or restrict by a maximum count, and apply actions like shutdown or restrict upon violation, directly addressing the requirement to prevent rogue devices.
Why the other options are wrong
- A. ACLs filter traffic based on IP addresses, port numbers, etc., but do not directly control which MAC addresses can connect to a physical port.
- C. 802.1X Authentication provides more robust, user-based authentication but requires an authentication server (e.g., RADIUS) and client software, which is not implied by 'learning MAC addresses' as the primary mechanism.
- D. DHCP Snooping is used to prevent rogue DHCP servers and protect against DHCP starvation attacks, not to restrict device access based on MAC addresses.
Port Security
Port Security is a Layer 2 security feature on switches that restricts input to an interface by limiting and identifying the MAC addresses of devices allowed to connect.
- Restricts access based on MAC addresses.
- Can be configured to learn MACs dynamically, statically, or sticky.
- Violation modes: shutdown, restrict, protect.
- Helps prevent MAC address spoofing and unauthorized access.
Memory trick: MAC Address Lock, No Rogue Devices Talk