Courseiva
mediumMultiple Choice

350-401 Practice Question: Examine the following interface configuration on…

Examine the following interface configuration on a Cisco IOS-XE switch: ```

interface GigabitEthernet0/1
 switchport mode access
 switchport port-security
 switchport port-security maximum 2
 switchport port-security violation restrict
 switchport port-security mac-address sticky

``` What is the effect of this configuration?

⚠ Common exam trap

Cisco often tests the distinction between violation modes ('shutdown', 'restrict', 'protect'), and the trap here is confusing 'restrict' with 'shutdown' or assuming 'restrict' silently drops all traffic, when in fact it only drops traffic from the violating MAC and logs the event.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The port will dynamically learn MAC addresses, allow up to 2 addresses, and if a third MAC is seen, it will drop the traffic but keep the port up.

The configuration sets port-security with a maximum of 2 MAC addresses, violation mode 'restrict', and sticky MAC learning. When a third MAC address is seen, the 'restrict' action drops traffic from that MAC but keeps the port up, generates a syslog message, and increments the violation counter. Option A correctly describes this behavior.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The port will dynamically learn MAC addresses, allow up to 2 addresses, and if a third MAC is seen, it will drop the traffic but keep the port up.

    Why this is correct

    With port security in violation mode restrict, the switch dynamically learns secure MAC addresses up to the configured maximum of two. When a third distinct source MAC appears, frames from that unknown MAC are dropped by the port, but the port remains administratively up and operational for the two learned addresses. Restrict does not disable the interface; it silently discards violating traffic and increments the security violation counter, which is exactly what this scenario describes.

  • ✗

    The port will learn up to 2 MAC addresses and then shut down if a third is seen.

    Why it's wrong here

    This answer incorrectly applies the shutdown violation action, which would place the port into an err-disabled state upon the third learned MAC. However, the configuration described uses restrict, not shutdown, so the interface is not disabled and no shutdown occurs. Shutdown mode also often requires manual intervention or errdisable recovery to bring the port back, whereas restrict keeps the port forwarding all frames from the permitted addresses.

  • ✗

    The port will allow only 2 MAC addresses and will generate a syslog message but continue forwarding traffic from the third MAC.

    Why it's wrong here

    This answer confuses restrict with a hybrid behavior that does not exist in port security. Under restrict, the switch drops frames from MAC addresses beyond the configured maximum and does NOT forward them, although it does generate logging/SNMP notifications and increments the violation counter. If the functionality described were accurate, it would be more like a monitoring-only feature, but restrict is explicitly a drop action, so the claim that traffic is still forwarded is incorrect.

  • ✗

    The port will learn MAC addresses dynamically and convert them to secure MAC addresses, but the maximum is 1 by default.

    Why it's wrong here

    Although the default maximum secure MAC addresses is indeed one when port security is enabled, the switchport port-security maximum 2 command has explicitly changed that limit to two in this scenario. Dynamic secure MAC addresses are learned and stored, but the configuration, not the default, determines the maximum, and the question states that the maximum is configured as 2. Therefore, saying the maximum is one by default ignores the explicit configuration that overrides that default.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.