350-401 Security Practice Question
A network administrator is deploying a new Cisco Catalyst 9200 switch at a branch office. The security policy requires that when a device connected to a port is shut down or moved, the switch must immediately send a SNMP trap and place the port into an error-disabled state while also incrementing a violation counter. The administrator configures port security with the violation mode that meets these requirements. Which command must be applied to the interface to achieve this?
⚠ Common exam trap
The trap here is assuming that restrict mode also error-disables the port, when in fact it only drops frames and logs the violation without shutting down the interface.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
switchport port-security violation shutdown
The security policy requires the switch to send an SNMP trap and place the port into an error-disabled state when a violation occurs. The shutdown violation mode does exactly that: it error-disables the port, generates a syslog/SNMP notification, and increments the violation counter. The restrict mode only increments counters and sends notifications without disabling the port, while protect mode silently drops frames. Disable is not a valid keyword.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
switchport port-security violation disable
Why it's wrong here
There is no violation mode called 'disable' in Cisco port security. The valid modes are protect, restrict, and shutdown. Configuring an invalid mode will result in a command rejection, so it cannot fulfill the requirement. The administrator must choose one of the three supported modes.
- ✗
switchport port-security violation restrict
Why it's wrong here
The restrict mode drops offending frames, increments the violation counter, and optionally generates a syslog or SNMP trap, but it does not error-disable the port. Since the policy requires the port to become error-disabled, restrict mode does not satisfy the requirement. It is used when continuous connectivity is preferred over shutting down the port.
- ✗
switchport port-security violation protect
Why it's wrong here
Protect mode silently drops frames with unknown source MAC addresses and does not increment the violation counter, generate a notification, or error-disable the port. This mode provides the least visibility and control, so it cannot meet the requirement for an immediate SNMP trap and error-disabled state.
- ✓
switchport port-security violation shutdown
Why this is correct
Shutdown mode causes the port to go into an error-disabled state immediately upon a violation, sends an SNMP trap, and increments the violation counter. This exactly matches the stated security policy. The port must be manually re-enabled with a shutdown/no shutdown sequence after the violation is resolved.
Go deeper
Related to this question
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.