Courseiva
Network Services and SecurityhardMultiple ChoiceObjective-mapped

CCNA Network Services and Security Practice Question

A company wants unauthorized devices plugged into unused wall ports to have as little chance of gaining access as possible. Which action most directly supports that goal?

⚠ Common exam trap

Don't confuse methods that limit or monitor access with those that completely prevent it. Focus on actions that eliminate the risk entirely.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Administratively disable unused switch ports.

Administratively shutting down unused switch ports most directly supports the goal because it eliminates the access point entirely. Option B, converting unused ports into trunks, would actually increase risk by potentially allowing VLAN hopping and unauthorized traffic. Option D, removing VLAN assignments from active user ports, does not address unused ports and could disrupt legitimate users by forcing them into the default VLAN. Disabling unused ports is a simple and effective hardening measure that reduces attack surface.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Administratively disable unused switch ports.

    Why this is correct

    Administratively disabling unused switch ports, typically with the shutdown command in interface configuration mode, places the port in an administratively down state so no device can establish link connectivity or pass traffic. This directly eliminates the exposure of unneeded wall jacks because even if a rogue device is physically plugged in, the switch will not forward frames or negotiate an active Layer 1 link. Unlike VLAN or trunk adjustments, this hardening step does not alter the operation of active user ports and is the industry-standard first-line defense against unauthorized access to unused infrastructure.

  • Convert every unused port into a trunk.

    Why it's wrong here

    Converting every unused port into a trunk does not stop unauthorized devices from connecting; in fact, it increases risk because trunk ports carry multiple VLANs and negotiate DTP, so an attacker connecting to such a port could potentially gain access to several VLANs. Trunks also require additional control-plane protections such as BPDU guard and root guard to be safe, and configuring them on unused ports creates unnecessary complexity without addressing the actual requirement of blocking physical access. This action expands rather than reduces the attack surface, making it counterproductive to the stated hardening goal.

    When this WOULD be correct

    If the question asked about optimizing network performance or allowing multiple VLANs for a specific purpose, converting unused ports into a trunk could be the correct answer. For instance, if a network administrator needs to consolidate VLAN traffic for efficiency, this option would be appropriate.

  • Enable Telnet on unused ports for monitoring.

    Why it's wrong here

    Enabling Telnet on unused ports is both insecure and unrelated to the goal of blocking unauthorized devices because Telnet transmits credentials and traffic in clear text and would require the port to carry management traffic. Additionally, Telnet is a management protocol that runs on the switch's VTY lines, not on individual physical switch ports, so the premise is technically invalid. This configuration would add a remote-access attack vector rather than preventing rogue devices from using the wall jacks, so it fails the hardening objective completely.

    When this WOULD be correct

    If the question asked about monitoring and managing network traffic on all ports, including unused ones, enabling Telnet could be seen as a way to track unauthorized access attempts. In such a scenario, the focus would be on visibility rather than prevention.

  • Remove all VLAN assignments from active user ports.

    Why it's wrong here

    Removing VLAN assignments from active user ports would disrupt legitimate users because those ports are actively used and need their assigned VLAN to reach network resources. The question specifically targets unused wall ports, so altering configuration on active ports does nothing to prevent someone from plugging into an unused port, which would still be in the default VLAN and operable. This approach misapplies VLAN hygiene to the wrong set of interfaces and would cause availability problems, not improve security against unauthorized physical access.

    When this WOULD be correct

    In a scenario where the question asks how to enhance security by isolating user devices from unauthorized access, and specifically mentions VLAN management, removing VLAN assignments from active ports could be correct if it prevents unauthorized access by segmenting the network effectively.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The 200-301 exam frequently reuses these exact scenarios with slightly different constraints.

Administratively disable unused switch ports.Correct answer

Why this is correct

Administratively disabling unused switch ports, typically with the shutdown command in interface configuration mode, places the port in an administratively down state so no device can establish link connectivity or pass traffic. This directly eliminates the exposure of unneeded wall jacks because even if a rogue device is physically plugged in, the switch will not forward frames or negotiate an active Layer 1 link. Unlike VLAN or trunk adjustments, this hardening step does not alter the operation of active user ports and is the industry-standard first-line defense against unauthorized access to unused infrastructure.

Convert every unused port into a trunk.Wrong answer — click to see why

Why this is wrong here

Converting unused ports into a trunk does not prevent unauthorized access; it actually allows multiple VLANs to be carried over a single link, potentially exposing sensitive data. This action could inadvertently grant access to unauthorized devices if they connect to these trunked ports.

★ When this WOULD be the correct answer

If the question asked about optimizing network performance or allowing multiple VLANs for a specific purpose, converting unused ports into a trunk could be the correct answer. For instance, if a network administrator needs to consolidate VLAN traffic for efficiency, this option would be appropriate.

Why candidates choose this

Candidates may choose this option because they associate trunk ports with increased network capacity and flexibility, mistakenly believing that it enhances security by managing VLANs effectively, rather than recognizing the security implications of unauthorized access.

Enable Telnet on unused ports for monitoring.Wrong answer — click to see why

Why this is wrong here

Enabling Telnet on unused ports does not prevent unauthorized access; instead, it creates a potential security vulnerability by allowing remote access to those ports. This action could expose the network to unauthorized monitoring or control.

★ When this WOULD be the correct answer

If the question asked about monitoring and managing network traffic on all ports, including unused ones, enabling Telnet could be seen as a way to track unauthorized access attempts. In such a scenario, the focus would be on visibility rather than prevention.

Why candidates choose this

Candidates may choose this option because they associate Telnet with network management and monitoring, mistakenly believing that enabling it on unused ports would provide oversight and security against unauthorized access.

Remove all VLAN assignments from active user ports.Wrong answer — click to see why

Why this is wrong here

Removing VLAN assignments from active user ports does not prevent unauthorized devices from accessing the network; it could disrupt legitimate user access instead. The goal is to secure unused ports, not impact active ones.

★ When this WOULD be the correct answer

In a scenario where the question asks how to enhance security by isolating user devices from unauthorized access, and specifically mentions VLAN management, removing VLAN assignments from active ports could be correct if it prevents unauthorized access by segmenting the network effectively.

Why candidates choose this

Candidates may choose this option thinking that removing VLAN assignments would enhance security by limiting access points, not realizing that it could inadvertently disrupt legitimate user connectivity.

Analysis generated from the official 200-301blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

About these practice questions

Courseiva writes every 200-301 question from scratch — 1,389 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.