220-1101 Networking Practice Question
A small office network uses a managed switch with port security enabled. A new employee connects their laptop to a configured port, but the laptop cannot obtain an IP address or communicate on the network. The link light on the switch port is on. Other ports in the same VLAN work correctly. Which of the following is the MOST likely cause?
⚠ Common exam trap
CompTIA often tests the distinction between a port being administratively down (link light off) versus a port that is up but blocking traffic due to security features like port security (link light on but no data passes).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The switch port has MAC address filtering enabled that does not include the laptop's MAC
Port security with MAC address filtering restricts which devices can communicate through a switch port based on their MAC address. Since the link light is on (Layer 1 is up) but the laptop cannot obtain an IP address or communicate, the switch is likely dropping frames from the laptop's MAC because it is not in the allowed MAC list. This prevents DHCP discovery and all other traffic, even though the physical connection is established.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The switch port has MAC address filtering enabled that does not include the laptop's MAC
Why this is correct
When port security uses MAC address filtering, the switch examines the source MAC of every inbound frame and compares it against a configured allow list. The laptop's frame is dropped at the data-link layer, so DHCP discovers never reach the server and no IP is assigned, even though the physical link is up and the LED is lit. This creates the exact symptom of a working cable but complete network unresponsiveness.
- ✗
The switch port is administratively shut down
Why it's wrong here
Issuing the 'shutdown' command on an interface places it in administratively down state, which causes the switch to stop sending link pulses. With no link pulses, the laptop's NIC would not establish carrier, so the link light would remain off. Since the scenario states the link light is on, the port cannot be administratively shut down.
- ✗
The laptop has a static IP address that conflicts with another device
Why it's wrong here
An IP address conflict is a Layer 3 problem: the laptop first completes Ethernet link and DHCP (or uses a static address), then two devices claim the same IPv4 address. The conflict results in ARP instability and intermittent loss of connectivity, not a failure to obtain an address. If the laptop used a static IP, it would still have a configured address and would be able to send frames at the data-link layer, which is not what 'no network access' with an active link describes.
- ✗
The switch port is not in the correct VLAN
Why it's wrong here
Assigning the switchport to the wrong VLAN does not block the link; the physical and data-link layers remain active and the laptop can still send frames to other devices in that same VLAN. The problem would be limited to an inability to reach resources in other VLANs unless inter-VLAN routing is missing, but the laptop would normally still obtain DHCP if a DHCP server exists in its VLAN. Because the symptom is complete failure to communicate with anything, a port-security MAC filter is the more precise cause.
Visual reference
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
Learn chapter
Wireless Security: WEP, WPA, WPA2, WPA3
Key term
Media Access Control
Media Access Control (MAC) is a sublayer of the Data Link Layer in networking that controls how devices on the same network share access to the physical medium and uniquely identifies each device with a hardware address.
About these practice questions
This 220-1101 question is part of Courseiva's 896-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1101 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1101 exam.