CCNA Network Services and Security Practice Question
You are configuring a Cisco switch port in a lobby area where only one device should ever connect. You want the port to learn the first MAC address it sees, and if a different MAC address appears later, you want the port to drop frames from the new address while still allowing the original device to communicate. Which port-security violation mode meets this requirement?
⚠ Common exam trap
Test-takers frequently confuse the quiet protect mode with restrict mode, which behaves identically except that it logs violations and increments counters.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
protect
Port security protect mode silently discards frames from any MAC address beyond the configured maximum and never logs or disables the port. This preserves connectivity for the first learned, authorized device while blocking the unexpected address, which is exactly the lobby scenario where only one device should be permitted.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
protect
Why this is correct
Protect mode drops frames from any MAC address that exceeds the maximum count but never generates a log or syslog message and never shuts the port down. The already-authorized MAC address continues to communicate normally, which matches the requirement of silently discarding traffic from the unexpected new device.
- ✗
shutdown
Why it's wrong here
Shutdown mode places the port into the err-disabled state on the first violation, which stops the original authorized device from communicating as well. Because the requirement states the original device should remain able to communicate, shutting the entire port down is clearly not the desired behavior.
- ✗
restrict
Why it's wrong here
Restrict mode also drops violating frames, but it increments the security violation counter and generates syslog messages and SNMP traps. That additional logging and alerting exceeds what was asked for, since the scenario only requires that the unexpected address be dropped while the legitimate device keeps working.
- ✗
err-disable
Why it's wrong here
Err-disable is not a port-security violation mode; it is the resulting state a port enters after certain violations, including the shutdown violation mode. Choosing it confuses the consequence of a violation with the configurable mode itself and would not produce the silent dropping behavior requested.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
Learn chapter
Hub vs Switch vs Router: Layer Differences
Key term
Protect mode
Protect mode is a security feature on Cisco switches that prevents a port from learning new MAC addresses once it exceeds a configured limit, but unlike errdisable, it does not shut down the port or generate an SNMP trap.
Key term
MAC address
A MAC address is a unique hardware identifier assigned to a network interface card that allows devices to communicate on a local network.
About these practice questions
This 200-301 question is part of Courseiva's 1,450-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.