350-401 Security Practice Question
A network administrator is configuring a Cisco Catalyst switch to prevent unauthorized devices from connecting to an access port. The administrator wants to ensure that only one MAC address is allowed on the port, and if a violation occurs, the port should be shut down and an SNMP trap sent. Which port security violation mode should be configured?
⚠ Common exam trap
Watch out — candidates often confuse the errdisable state with a configurable violation mode, or assuming restrict mode also shuts down the port.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
shutdown
The shutdown violation mode meets both requirements: it shuts down the port (error-disabled) and sends an SNMP trap. Protect mode only drops traffic, restrict mode drops and sends traps but does not shut down the port. Errdisable is a state, not a mode. Thus, shutdown is the correct configuration for this security policy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
protect
Why it's wrong here
Protect mode drops packets from unauthorized MAC addresses but does not shut down the port or send an SNMP trap. It silently discards violating traffic, which does not meet the requirement of shutting down the port and generating an SNMP trap. Therefore, it is not the correct mode for this scenario.
- ✗
restrict
Why it's wrong here
Restrict mode drops packets from unauthorized MAC addresses, increments the violation counter, and sends an SNMP trap, but it does not shut down the port. The scenario explicitly requires the port to be shut down upon violation, so restrict mode alone is insufficient. It would send a trap but leave the port operational, allowing further violation attempts.
- ✗
errdisable
Why it's wrong here
Errdisable is not a port security violation mode; it is a state that a port enters due to various errors, including port security violations in shutdown mode. Configuring 'errdisable' as a violation mode is invalid. The correct mode that causes error-disabled state is 'shutdown'. This option confuses the resulting state with the configurable mode.
- ✓
shutdown
Why this is correct
Shutdown mode places the port into an error-disabled state when a violation occurs, effectively shutting it down. It also sends an SNMP trap and syslog message. This matches the requirement to shut down the port and send an SNMP trap. The port can be recovered manually or via errdisable recovery. This is the correct violation mode for the described policy.
Visual reference
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.