hardMultiple ChoiceObjective-mapped
220-1201 Practice Question: A technician is troubleshooting a network where…
A technician is troubleshooting a network where users on one floor cannot access a server on another floor. Both floors are connected via a single fiber optic link. The technician checks the link and sees the switch port shows 'err-disabled' status. What is the most likely cause of this state?
⚠ Common exam trap
The 220-1201 exam often tests the distinction between physical link issues (cable damage, duplex mismatch) and software-induced states like 'err-disabled', where candidates mistakenly attribute the state to hardware faults rather than security or error-disable mechanisms.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Port security has been violated
The 'err-disabled' state on a switch port is commonly triggered by a port security violation. When a device attempts to connect with a MAC address that exceeds the configured maximum or is not on the allowed list, the switch disables the port to prevent unauthorized access. This matches the scenario where users on one floor cannot reach a server, as the link is physically intact but logically blocked.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The fiber cable is damaged
Why it's wrong here
A damaged fiber cable, such as a break or severe bend, would typically prevent the physical layer from establishing a link. This would manifest as the port status being 'down' or 'notconnect', indicating a lack of physical connectivity or light signal. The 'err-disabled' state, however, is a logical shutdown imposed by the switch's operating system in response to a specific policy violation, not a physical layer fault.
- ✗
A duplex mismatch exists between the switches
Why it's wrong here
A duplex mismatch occurs when one side of a link operates in full-duplex mode while the other operates in half-duplex. This condition leads to severe performance degradation, high collision counts, and excessive frame errors, as devices attempt to transmit simultaneously or wait unnecessarily. While it significantly impairs network communication, a duplex mismatch does not typically trigger the 'err-disabled' state; instead, the port remains logically 'up' but experiences severe operational issues.
- ✓
Port security has been violated
Why this is correct
Port security is a feature designed to prevent unauthorized devices from connecting to a switch port by limiting the number of MAC addresses allowed on that port. When a violation occurs, such as an unknown MAC address attempting to connect or the maximum allowed MAC addresses being exceeded, the switch's default action is often to shut down the port. This shutdown state is known as 'err-disabled', effectively isolating the offending device and preventing further unauthorized access.
- ✗
The VLAN configuration is incorrect
Why it's wrong here
An incorrect VLAN configuration, such as assigning a port to the wrong VLAN or misconfiguring trunking, would primarily result in traffic not being forwarded to the intended destination or devices being unable to communicate with others in their expected broadcast domain. While this causes significant connectivity issues, the port itself would typically remain in an 'up' state. VLAN misconfigurations do not trigger the switch's err-disabled security mechanism, which is reserved for specific policy violations.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
Learn chapter
Mobile Device Types and Features
Key term
MAC
MAC (Media Access Control) is a unique hardware identifier assigned to network interfaces for communication on a local network segment.
Key term
MAC address
A MAC address is a unique hardware identifier assigned to a network interface card that allows devices to communicate on a local network.
About these practice questions
Courseiva writes every 220-1201 question from scratch — 972 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1201 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1201 exam.