CCNP Security Practice Question
A network engineer is configuring port security on a Cisco switch to prevent unauthorized devices from connecting. The requirement is to allow only the first two MAC addresses learned on an interface, and to disable the interface if a violation occurs. Which configuration achieves this?
⚠ Common exam trap
Cisco often tests the distinction between 'shutdown' (disables the interface) and 'restrict' (drops traffic but keeps the interface up), leading candidates to confuse the two when the requirement explicitly calls for disabling the interface.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
switchport port-security maximum 2 switchport port-security violation shutdown
The 'shutdown' violation mode places the interface into an err-disabled state when a port security violation occurs, which matches the requirement to disable the interface. The 'maximum 2' command limits the number of allowed MAC addresses to two, and the first two learned MAC addresses are dynamically secured. This combination ensures that any additional MAC address triggers a violation and disables the port.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
switchport port-security maximum 2 switchport port-security violation err-disable
Why it's wrong here
The command 'switchport port-security violation err-disable' is invalid on Cisco IOS because the violation mode parameter only accepts the keywords 'shutdown', 'protect', or 'restrict'. The err-disable state is not a configurable mode; it is a condition that results from entering the 'shutdown' violation mode when an unauthorized MAC address appears. Therefore, this option would be rejected by the CLI and cannot be applied to the interface.
- ✓
switchport port-security maximum 2 switchport port-security violation shutdown
Why this is correct
This is the correct configuration. It sets the maximum number of secure MAC addresses to 2 and also specifies the violation action as 'shutdown'. When a third MAC address attempts to use the port, the switch places the interface in an err-disabled state, which completely disables the port and blocks all traffic, satisfying the requirement to disable the interface upon a violation.
- ✗
switchport port-security maximum 2 switchport port-security violation protect
Why it's wrong here
This option incorrectly uses the 'protect' violation mode, which does not disable the interface. When the configured maximum of 2 MAC addresses is exceeded, the port continues to operate normally for permitted addresses, and frames from unknown MAC addresses are silently dropped. Because the interface remains up and forwarding, it fails the explicit requirement that the port be disabled when a violation occurs.
- ✗
switchport port-security maximum 2 switchport port-security violation restrict
Why it's wrong here
The 'restrict' violation mode drops frames from unauthorized MAC addresses and increments a violation counter, but it does not place the port in an err-disabled state. Even after the maximum of 2 addresses is exceeded, the interface stays operational and continues forwarding traffic for the already-learned secure MAC addresses. This behavior does not meet the requirement to disable the interface, making the option incorrect.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.