CompTIA Network+ (N10-009)Network SecurityMedium
A network engineer is configuring a new switch that will connect to several user workstations. To prevent unauthorized devices from connecting to the network and to ensure that only specific MAC addresses are allowed on certain ports, which security feature should be enabled?
- ASpanning Tree Protocol (STP)
- BPort Mirroring
- CDHCP Snooping
- D802.1X
Show answer & explanationAnswer & explanation
Correct answer: D. 802.1X
802.1X is a port-based network access control protocol that provides authentication to devices attempting to connect to a network. It ensures that only authorized devices and users can gain access.
Why the other options are wrong
- A. Spanning Tree Protocol (STP) prevents network loops.
- B. Port Mirroring (SPAN) copies network traffic from one port to another for monitoring purposes.
- C. DHCP Snooping prevents unauthorized DHCP servers and protects against DHCP starvation attacks.
802.1X
An IEEE standard for port-based Network Access Control (NAC) that provides an authentication mechanism to devices wishing to attach to a LAN or WLAN.
- Requires devices to authenticate before gaining network access.
- Uses an authenticator (switch/AP), supplicant (client), and authentication server (RADIUS).
- Can enforce policies based on user, device, or group.
Memory trick: Access control: Who gets in, and what they can do.