Courseiva

CCNA Network Services and Security Practice Question

A junior administrator is configuring a Cisco switch port that connects to a conference room wall jack. The requirement is that only the first device that connects may use the port, and if any other MAC address is seen, the port should immediately go into an error-disabled state and require manual recovery. Which port security configuration should be applied?

⚠ Common exam trap

Many candidates confuse restrict mode with shutdown mode, since both drop unauthorized traffic, but only shutdown places the port into the error-disabled state.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

switchport port-security violation shutdown

Port security shutdown violation mode err-disables the interface when a MAC address that exceeds the allowed set is detected. Because the scenario requires only the first device to be permitted and immediate disabling upon any other MAC address, the default maximum of 1 combined with shutdown violation is appropriate. Manual recovery is then needed to bring the port back into service.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    switchport port-security maximum 2

    Why it's wrong here

    Setting the maximum to 2 allows two MAC addresses on the port, which contradicts the requirement that only the first device may connect. This command also does not define the violation action, so it does not ensure the port becomes error-disabled when an unauthorized device appears. The default violation action is shutdown, but the maximum value is wrong.

  • ✗

    switchport port-security violation protect

    Why it's wrong here

    Protect mode silently drops frames from unauthorized MAC addresses but does not generate a log message and does not err-disable the port. The port would continue passing traffic from the authorized device while discarding others, which does not meet the requirement to immediately disable the port and require manual recovery.

  • ✓

    switchport port-security violation shutdown

    Why this is correct

    Shutdown mode is the default violation behavior. When an unauthorized MAC address is detected, the switch places the port into the error-disabled state, effectively shutting it down. The port must then be manually re-enabled with the shutdown and no shutdown commands or by using errdisable recovery. This exactly matches the stated requirement.

  • ✗

    switchport port-security violation restrict

    Why it's wrong here

    Restrict mode drops unauthorized frames and generates syslog and SNMP traps, and increments the security violation counter, but it does not put the port into an error-disabled state. The port remains up for the authorized MAC address, so it does not satisfy the requirement for immediate err-disable and manual recovery.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

Go deeper

Related to this question

About these practice questions

Courseiva writes every 200-301 question from scratch — 1,450 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.