Cisco Certified Support Technician (CCST) NetworkingNetwork AccessEasy
A network administrator is configuring a new Cisco Catalyst switch and needs to enable a feature that prevents unauthorized devices from connecting to specific access ports by limiting the number of MAC addresses allowed on a port and defining the action to take when a violation occurs. Which of the following features should the administrator configure?
- ALink Aggregation Control Protocol (LACP)
- BPort Security
- CVLAN tagging
- DSpanning Tree Protocol (STP)
Show answer & explanationAnswer & explanation
Correct answer: B. Port Security
Port Security is a switch feature that allows administrators to control which devices can connect to a specific switch port by limiting the number of MAC addresses and defining violation actions. This prevents unauthorized access to the network.
Why the other options are wrong
- A. Link Aggregation Control Protocol (LACP) is used to bundle multiple physical links into a single logical link for increased bandwidth and redundancy, not for port access control.
- C. VLAN tagging is used to segment broadcast domains and allow multiple VLANs over a single link, not for access control on a port.
- D. Spanning Tree Protocol (STP) is used to prevent loops in a switched network, not to control device access.
Port Security
A Cisco switch feature that allows administrators to restrict access to a specific switch port by limiting the number of MAC addresses allowed to connect to it and defining actions for security violations.
- Limits the number of MAC addresses learned on a port.
- Can specify MAC addresses statically or learn dynamically.
- Defines violation modes (shutdown, restrict, protect) when unauthorized MACs are detected.
Memory trick: Switches Guard Access Points Rigorously.