Courseiva
Security →mediumMultiple Choice

CCNP Security Practice Question

A network engineer is configuring port security on a Cisco switch to prevent unauthorized devices from connecting. The requirement is to allow only the first two MAC addresses learned on an interface, and to disable the interface if a violation occurs. Which configuration achieves this?

⚠ Common exam trap

Cisco often tests the distinction between 'shutdown' (disables the interface) and 'restrict' (drops traffic but keeps the interface up), leading candidates to confuse the two when the requirement explicitly calls for disabling the interface.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

switchport port-security maximum 2 switchport port-security violation shutdown

The 'shutdown' violation mode places the interface into an err-disabled state when a port security violation occurs, which matches the requirement to disable the interface. The 'maximum 2' command limits the number of allowed MAC addresses to two, and the first two learned MAC addresses are dynamically secured. This combination ensures that any additional MAC address triggers a violation and disables the port.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    switchport port-security maximum 2 switchport port-security violation err-disable

    Why it's wrong here

    The command 'switchport port-security violation err-disable' is invalid on Cisco IOS because the violation mode parameter only accepts the keywords 'shutdown', 'protect', or 'restrict'. The err-disable state is not a configurable mode; it is a condition that results from entering the 'shutdown' violation mode when an unauthorized MAC address appears. Therefore, this option would be rejected by the CLI and cannot be applied to the interface.

  • ✓

    switchport port-security maximum 2 switchport port-security violation shutdown

    Why this is correct

    This is the correct configuration. It sets the maximum number of secure MAC addresses to 2 and also specifies the violation action as 'shutdown'. When a third MAC address attempts to use the port, the switch places the interface in an err-disabled state, which completely disables the port and blocks all traffic, satisfying the requirement to disable the interface upon a violation.

  • ✗

    switchport port-security maximum 2 switchport port-security violation protect

    Why it's wrong here

    This option incorrectly uses the 'protect' violation mode, which does not disable the interface. When the configured maximum of 2 MAC addresses is exceeded, the port continues to operate normally for permitted addresses, and frames from unknown MAC addresses are silently dropped. Because the interface remains up and forwarding, it fails the explicit requirement that the port be disabled when a violation occurs.

  • ✗

    switchport port-security maximum 2 switchport port-security violation restrict

    Why it's wrong here

    The 'restrict' violation mode drops frames from unauthorized MAC addresses and increments a violation counter, but it does not place the port in an err-disabled state. Even after the maximum of 2 addresses is exceeded, the interface stays operational and continues forwarding traffic for the already-learned secure MAC addresses. This behavior does not meet the requirement to disable the interface, making the option incorrect.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.