Courseiva
Security →mediumMultiple Choice

CCNP Security Practice Question

A network administrator is deploying a Cisco Catalyst 9300 switch stack at the access layer. The security policy requires that when an endpoint device is connected to a port and later replaced by a different device, the port must automatically learn the new MAC address without administrative intervention, but a violation must generate a syslog message and increment a counter. The administrator configures the interface with the command 'switchport port-security violation restrict'. Which additional command is required to meet the requirement that the new device is learned automatically?

⚠ Common exam trap

The trap here is assuming that setting a maximum or aging time enables automatic learning of a replacement device, when only sticky learning dynamically adds the new MAC to the configuration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

switchport port-security mac-address sticky

Sticky learning allows the switch to dynamically learn MAC addresses and add them to the running configuration, so when a device is replaced, the new MAC can be learned without manual reconfiguration. Combining sticky with violation restrict ensures a syslog and counter increment on violation. Maximum, static MAC, and aging do not provide the required automatic learning behavior.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    switchport port-security aging time 2

    Why it's wrong here

    Aging time controls how long a dynamically learned secure MAC remains in the table before being removed. It does not by itself enable the port to learn a new MAC after replacement; without sticky learning, the original MAC may persist until aged out, and the new device may still be blocked depending on timing. It does not guarantee automatic learning as required.

  • ✓

    switchport port-security mac-address sticky

    Why this is correct

    Sticky learning dynamically learns the MAC address of the first device and adds it to the running configuration. When the device is replaced, the old sticky entry can age out or be removed, and the new device is learned. With violation restrict, a syslog and counter increment occur on violation. This meets the requirement without manual intervention, unlike static configuration.

  • ✗

    switchport port-security maximum 1

    Why it's wrong here

    Setting the maximum to 1 limits the port to one MAC address but does not allow automatic learning of a new device after replacement. The original MAC remains in the secure table, so the new device triggers a violation and is not learned. The requirement is automatic learning, which maximum alone does not provide.

  • ✗

    switchport port-security mac-address 0011.2233.4455

    Why it's wrong here

    This statically assigns a specific MAC address to the port. If the device is replaced with a different MAC, the new device will cause a violation and will not be learned automatically. Static entries require manual reconfiguration, contradicting the automatic learning requirement.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.