CCNP Security Practice Question
A network administrator is deploying a Cisco Catalyst 9300 switch stack at the access layer. The security policy requires that when an unauthorized device connects to an access port, the port must immediately stop forwarding traffic, generate a syslog message, and increment the violation counter, while allowing the administrator to manually re-enable the port after investigation. Which port security violation mode should be configured?
⚠ Common exam trap
The trap here is assuming that restrict mode shuts down the port because it logs violations, when in fact only shutdown mode err-disables the interface.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
shutdown
Port security shutdown mode is the only violation action that immediately err-disables the interface, halts forwarding, logs a syslog message, increments the violation counter, and requires manual recovery. Protect and restrict leave the port up, and err-disable recovery is a global timer feature rather than a violation mode. The stated need for manual re-enablement after investigation confirms shutdown is correct.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
err-disable recovery
Why it's wrong here
Err-disable recovery is a global configuration feature that automatically re-enables err-disabled ports after a timer expires; it is not a port security violation mode. Configuring it would contradict the requirement for manual re-enablement because the port would come back online automatically. The scenario asks which violation mode to set on the interface, and err-disable recovery is a separate recovery mechanism, not a violation action.
- ✗
protect
Why it's wrong here
Protect mode silently drops frames from unknown MAC addresses without generating a syslog message or incrementing the violation counter. The scenario explicitly requires a syslog message and counter increment, so protect does not satisfy the logging requirement. It also does not place the port in an err-disabled state, meaning the port keeps forwarding legitimate traffic, which violates the requirement to immediately stop forwarding traffic on violation.
- ✗
restrict
Why it's wrong here
Restrict mode drops violating frames, generates a syslog message, and increments the violation counter, but it does not shut down the port. Because the requirement states the port must immediately stop forwarding traffic and require manual re-enablement, restrict falls short. Administrators often confuse restrict with shutdown because both log violations, but only shutdown err-disables the interface and demands administrative intervention.
- ✓
shutdown
Why this is correct
Shutdown mode places the port into an err-disabled state immediately upon a violation, stops all forwarding, generates a syslog message, and increments the violation counter. Recovery requires manual intervention (or err-disable recovery configuration), matching the scenario's requirement that the administrator re-enable the port after investigation. This is the classic default violation mode on Cisco Catalyst switches and satisfies every stated condition.
Visual reference
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.