Courseiva
mediumMultiple SelectObjective-mapped

350-701 Practice Question: A network administrator is configuring port…

A network administrator is configuring port security on a Cisco switch port connected to a single endpoint. The requirement is that only the first device that connects to the port is allowed, and any subsequent device that attempts to connect must trigger an error-disabled state. Which two features must be configured to meet this requirement?

⚠ Common exam trap

Cisco often tests the misconception that the 'violation shutdown' command must be explicitly configured, when in fact it is the default violation mode for port security, so candidates incorrectly include it as a required feature instead of recognizing that the maximum and sticky commands are the two necessary configurations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

switchport port-security mac-address sticky

The 'switchport port-security mac-address sticky' command dynamically learns the MAC address of the first connected device and saves it as a sticky secure MAC address in the running configuration. Option E is correct because setting the maximum number of secure MAC addresses to 1 ensures that only the first device's MAC address is allowed; any additional device will trigger a security violation. Together, these two features enforce that only the first device can connect, and subsequent devices cause the port to enter an error-disabled state when combined with the shutdown violation mode.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • switchport port-security aging type inactivity

    Why it's wrong here

    Aging is not required for this requirement.

  • switchport port-security mac-address sticky

    Why this is correct

    Sticky learning dynamically learns and remembers the first MAC.

  • switchport port-security mac-address 0000.1111.2222

    Why it's wrong here

    Manually specifying a MAC address would not allow the first device to be automatically learned.

  • switchport port-security violation shutdown

    Why it's wrong here

    Shutdown is the default violation action, so it is not required to be explicitly configured.

  • switchport port-security maximum 1

    Why this is correct

    Limits the port to a single MAC address.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

Courseiva writes every 350-701 question from scratch — 978 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-701 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-701 exam.