Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Network SecurityMedium

A network technician is configuring a new switch in a data center. To enhance security and prevent unauthorized devices from connecting to the network, the technician wants to ensure that only specific, known MAC addresses are allowed on certain switch ports. If an unknown MAC address attempts to connect, the port should automatically shut down. Which switch security feature should the technician configure?

  1. APort mirroring
  2. BPort security
  3. CSTP (Spanning Tree Protocol)
  4. DVLAN tagging
Show answer & explanation

Correct answer: B. Port security

Port security is a Cisco switch feature (and similar features exist on other vendors) that allows administrators to restrict input access to a port based on MAC addresses. It can be configured to allow only specific MAC addresses, learn a certain number of MAC addresses, and take actions like shutting down the port if a violation occurs.

Why the other options are wrong

  • A. Port mirroring copies traffic from one port to another for monitoring, not for access control.
  • C. STP prevents network loops but does not control which devices can connect to a port based on MAC address.
  • D. VLAN tagging logically segments networks but doesn't restrict devices based on MAC address on a specific port.

Port Security

A switch feature that restricts input to a port based on the MAC addresses of connected devices, preventing unauthorized access.

  • Limits the number of MAC addresses allowed on a port.
  • Can statically define allowed MAC addresses.
  • Violation modes include shutdown, restrict, and protect.
  • Helps mitigate MAC spoofing and unauthorized device connections.

Memory trick: Port security is like having a bouncer at each club door, only letting in approved guests.

More Network Security questions