mediumMultiple Choice
350-401 Practice Question: Is configuring port security on a Cisco switch
A network engineer is configuring port security on a Cisco switch. The requirement is to allow only the first MAC address that appears on the port to be learned and to automatically disable the port if a violation occurs. The engineer configures 'switchport port-security mac-address sticky' but does not specify a maximum number of secure MAC addresses. After connecting a single host, the port works. However, when the host is replaced with a different device, the port is error-disabled. What is the most likely reason?
⚠ Common exam trap
Cisco often tests the default values for port security features, specifically that the default maximum number of secure MAC addresses is 1 and the default violation mode is 'shutdown', leading candidates to overlook the need to configure 'switchport port-security maximum' when using sticky learning for multiple hosts.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The default maximum number of secure MAC addresses is 1, so the second MAC address triggers a violation.
The default maximum number of secure MAC addresses on a switchport is 1. When the engineer configured 'switchport port-security mac-address sticky' without specifying a maximum, the port learned the first host's MAC address as a sticky entry. When a different device was connected, its MAC address exceeded the default limit of 1, triggering a security violation. Since the default violation mode is 'shutdown', the port was error-disabled.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The default maximum number of secure MAC addresses is 1, so the second MAC address triggers a violation.
Why this is correct
Port security defaults to a maximum of one secure MAC address per port, so the sticky command alone does not raise that limit. When the replacement device presents a second MAC, the default maximum is exceeded and the violation mode error-disables the port.
- ✗
The sticky keyword requires the engineer to first manually configure a maximum number of MAC addresses.
Why it's wrong here
Sticky learning needs no pre-configured maximum; the default maximum of one secure MAC address already applies, so the second device triggers a violation. It is tempting because sticky addresses are saved to the running configuration, which sounds like it requires prior manual sizing, and would be correct if the engineer wanted to reserve several addresses before any host connected.
- ✗
The violation mode is set to 'restrict' by default, which causes the port to error-disable after one violation.
Why it's wrong here
The default violation mode is shutdown, not restrict; restrict drops offending frames and logs them while leaving the port up, so it cannot explain the error-disabled state. It is tempting because restrict is a real port-security mode that responds to violations, and would be correct if the engineer had configured restrict and the port had stayed operational.
- ✗
The port security aging type is set to 'absolute' by default, causing the sticky address to expire immediately.
Why it's wrong here
Aging is disabled by default on Cisco port security, so sticky addresses never expire unless the engineer explicitly configures 'switchport port-security aging time'. It is tempting because absolute aging does remove secure addresses, and would be the right explanation if the engineer had actually enabled aging with a short timer, which the scenario does not state.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.