Courseiva
Networking →hardMultiple Choice

220-1101 Networking Practice Question

A technician connects a new workstation to a switch port that is configured with port security and a maximum of one MAC address. After connecting the workstation, the port link LED remains off. The technician has verified the Ethernet cable is good, the switchport is not administratively down, and the workstation's NIC is functioning. Which of the following is the MOST likely cause?

⚠ Common exam trap

CompTIA often tests the misconception that a port security violation only blocks traffic while keeping the link up, but in the default 'shutdown' mode, the port is actually error-disabled and the link LED turns off, which candidates may confuse with a physical cabling or VLAN issue.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The workstation's MAC address violates port security, causing the port to error-disable

Port security with a maximum of one MAC address will place the port into an error-disabled state if a MAC address violation occurs, such as when the workstation's MAC address differs from the one already learned or when the port detects a new MAC after the limit is reached. The link LED being off indicates the port is administratively up but not operational, which is consistent with an error-disabled condition caused by a security violation. Since the cable, switchport status, and NIC are verified good, the most likely cause is that the workstation's MAC triggered a port security violation, disabling the port.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The switchport is configured for a different VLAN than the workstation

    Why it's wrong here

    A VLAN mismatch would not prevent the link from coming up; the port LED would typically light and the workstation might not obtain an IP address. The link LED being off indicates a Layer 1 or Layer 2 error such as a security violation.

  • ✓

    The workstation's MAC address violates port security, causing the port to error-disable

    Why this is correct

    Port security with a limit of one MAC address will only allow that specific learned MAC to communicate. When a new MAC is detected, a violation occurs, and the port is error-disabled, turning off the link LED. This is the most likely cause given the symptoms.

  • ✗

    The switch requires a reboot to recognize the new workstation

    Why it's wrong here

    A switch does not require a reboot to add or recognize a new workstation; MAC address learning is a continuous, dynamic process that occurs whenever a frame is received on a port. Rebooting would only temporarily clear the MAC address table and could actually mask the real problem, such as an error-disabled port. Since the link LED is off, the issue is a Layer 1/2 condition like a security violation, not a need for the switch to restart.

  • ✗

    The workstation has a duplicate IP address on the network

    Why it's wrong here

    A duplicate IP address would cause network conflicts but would typically still allow the link LED to be on. The port LED being off indicates the switch port is not active at Layer 1, which is not caused by an IP address conflict.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

Go deeper

Related to this question

About these practice questions

One of 896 original 220-1101 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1101 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1101 exam.