Cisco Certified Support Technician (CCST) NetworkingNetwork AccessMedium

A network administrator is configuring a new Cisco switch. The administrator wants to ensure that specific MAC addresses are allowed on a port, and any other MAC addresses attempting to connect will be immediately shut down, requiring manual intervention to re-enable the port. Which port security violation mode should be configured?

  1. ATrap
  2. BProtect
  3. CShutdown
  4. DRestrict
Show answer & explanation

Correct answer: C. Shutdown

The 'Shutdown' violation mode disables the port immediately upon a security violation, placing it in an error-disabled (err-disable) state, and requiring manual intervention (or an auto-recovery timer) to bring it back up. This matches the requirement for immediate shutdown and manual re-enabling.

Why the other options are wrong

  • A. Trap is not a standard port security violation mode on Cisco switches; it's an action taken by 'Restrict' mode.
  • B. Protect mode drops packets from unauthorized MACs but does not send an SNMP trap or disable the port.
  • D. Restrict mode drops packets from unauthorized MACs and sends an SNMP trap, but does not disable the port.

Port Security Violation Modes

Actions a switch takes when an unauthorized device or too many MAC addresses are detected on a port configured with port security.

  • Protect: drops unauthorized traffic.
  • Restrict: drops unauthorized traffic, sends SNMP trap, increments counter.
  • Shutdown: disables the port and puts it in err-disable state.

Memory trick: P-R-S: Protect, Restrict, Shutdown – each more severe.

More Network Access questions