CCNA Network Services and Security Practice Question
A junior administrator is configuring a Cisco switch port that connects to a conference room wall jack. The requirement is that only the first device that connects may use the port, and if any other MAC address is seen, the port should immediately go into an error-disabled state and require manual recovery. Which port security configuration should be applied?
⚠ Common exam trap
Many candidates confuse restrict mode with shutdown mode, since both drop unauthorized traffic, but only shutdown places the port into the error-disabled state.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
switchport port-security violation shutdown
Port security shutdown violation mode err-disables the interface when a MAC address that exceeds the allowed set is detected. Because the scenario requires only the first device to be permitted and immediate disabling upon any other MAC address, the default maximum of 1 combined with shutdown violation is appropriate. Manual recovery is then needed to bring the port back into service.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
switchport port-security maximum 2
Why it's wrong here
Setting the maximum to 2 allows two MAC addresses on the port, which contradicts the requirement that only the first device may connect. This command also does not define the violation action, so it does not ensure the port becomes error-disabled when an unauthorized device appears. The default violation action is shutdown, but the maximum value is wrong.
- ✗
switchport port-security violation protect
Why it's wrong here
Protect mode silently drops frames from unauthorized MAC addresses but does not generate a log message and does not err-disable the port. The port would continue passing traffic from the authorized device while discarding others, which does not meet the requirement to immediately disable the port and require manual recovery.
- ✓
switchport port-security violation shutdown
Why this is correct
Shutdown mode is the default violation behavior. When an unauthorized MAC address is detected, the switch places the port into the error-disabled state, effectively shutting it down. The port must then be manually re-enabled with the shutdown and no shutdown commands or by using errdisable recovery. This exactly matches the stated requirement.
- ✗
switchport port-security violation restrict
Why it's wrong here
Restrict mode drops unauthorized frames and generates syslog and SNMP traps, and increments the security violation counter, but it does not put the port into an error-disabled state. The port remains up for the authorized MAC address, so it does not satisfy the requirement for immediate err-disable and manual recovery.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
Learn chapter
Troubleshoot: Switch Interface Down
Key term
Media Access Control
Media Access Control (MAC) is a sublayer of the Data Link Layer in networking that controls how devices on the same network share access to the physical medium and uniquely identifies each device with a hardware address.
Key term
Interface
An interface is a point of connection or interaction between two systems, devices, or software components that allows them to exchange information or signals.
About these practice questions
Courseiva writes every 200-301 question from scratch — 1,450 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.