CCNP Security Practice Question
A network administrator is deploying a Cisco Catalyst 9300 switch stack at the access layer. The security policy requires that when an endpoint device is connected to a port and later replaced by a different device, the port must automatically learn the new MAC address without administrative intervention, but a violation must generate a syslog message and increment a counter. The administrator configures the interface with the command 'switchport port-security violation restrict'. Which additional command is required to meet the requirement that the new device is learned automatically?
⚠ Common exam trap
The trap here is assuming that setting a maximum or aging time enables automatic learning of a replacement device, when only sticky learning dynamically adds the new MAC to the configuration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
switchport port-security mac-address sticky
Sticky learning allows the switch to dynamically learn MAC addresses and add them to the running configuration, so when a device is replaced, the new MAC can be learned without manual reconfiguration. Combining sticky with violation restrict ensures a syslog and counter increment on violation. Maximum, static MAC, and aging do not provide the required automatic learning behavior.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
switchport port-security aging time 2
Why it's wrong here
Aging time controls how long a dynamically learned secure MAC remains in the table before being removed. It does not by itself enable the port to learn a new MAC after replacement; without sticky learning, the original MAC may persist until aged out, and the new device may still be blocked depending on timing. It does not guarantee automatic learning as required.
- ✓
switchport port-security mac-address sticky
Why this is correct
Sticky learning dynamically learns the MAC address of the first device and adds it to the running configuration. When the device is replaced, the old sticky entry can age out or be removed, and the new device is learned. With violation restrict, a syslog and counter increment occur on violation. This meets the requirement without manual intervention, unlike static configuration.
- ✗
switchport port-security maximum 1
Why it's wrong here
Setting the maximum to 1 limits the port to one MAC address but does not allow automatic learning of a new device after replacement. The original MAC remains in the secure table, so the new device triggers a violation and is not learned. The requirement is automatic learning, which maximum alone does not provide.
- ✗
switchport port-security mac-address 0011.2233.4455
Why it's wrong here
This statically assigns a specific MAC address to the port. If the device is replaced with a different MAC, the new device will cause a violation and will not be learned automatically. Static entries require manual reconfiguration, contradicting the automatic learning requirement.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.