MAC Address Filtering & Port Security — Troubleshooting No IP Address
A technician connects a new workstation to a wall jack in an office. The link lights on both the workstation's NIC and the switch port are solid green. The workstation cannot obtain an IP address via DHCP. The technician manually assigns a static IP address in the same subnet as other working workstations (192.168.1.100/24, gateway 192.168.1.1), but the workstation still cannot ping the gateway or any other device on the network. Other workstations connected to the same switch can access network resources normally. Which of the following is the MOST likely cause of this issue?
Quick Answer
The combination of details in this question is designed to guide you specifically toward a Layer 2 access control feature rather than a cabling, addressing, or DHCP problem. Solid link lights on both the workstation's NIC and the switch port confirm that the physical connection itself, Layer 1, is completely healthy, which rules out a bad cable or a faulty port. Yet the workstation cannot obtain an address via DHCP, and even manually assigning a valid static IP address in the correct subnet still fails to produce any connectivity at all, not even a ping to the gateway, while other workstations on that same switch work normally. A failure this total, affecting both automatic and manually configured addressing, while the physical link stays up, points to something actively filtering traffic based on identity rather than a configuration mistake, since a simple misconfiguration wouldn't typically block a correctly addressed static IP as well. Port security is designed to do exactly this: it restricts a switch port to specific authorized MAC addresses and blocks all traffic from anything else, regardless of whether that traffic is a DHCP request or already has a valid IP address. Whenever a device has a confirmed physical connection but cannot communicate at all, even after manually assigning correct addressing, and other devices on the same switch work fine, consider port security or another MAC-based filtering mechanism before continuing to troubleshoot addressing.
⚠ Common exam trap
The trap here is that candidates see solid link lights and assume Layer 1 is fully operational, forgetting that port security can block traffic at Layer 2 while keeping the port administratively up, leading them to incorrectly blame a faulty cable or IP conflict.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The switch port has port security enabled, and the workstation's MAC address is not allowed
The solid link lights indicate Layer 1 connectivity is good, ruling out a faulty cable. The inability to obtain an IP via DHCP and the failure to ping the gateway even with a manually assigned static IP in the correct subnet point to a Layer 2 filtering mechanism. Port security on the switch port is the most likely cause, as it would block all traffic from an unauthorized MAC address, preventing DHCP discovery and any subsequent communication, even with a valid static IP.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The switch port has port security enabled, and the workstation's MAC address is not allowed
Why this is correct
Port security restricts the switch port to specific permitted MAC addresses; an unlisted workstation's frames are dropped, so DHCP and static addressing both fail while other ports work. This matches the stem's symptom of solid link lights but no connectivity.
- ✗
The IP address 192.168.1.100 is already in use by another device
Why it's wrong here
A duplicate IP address would cause an IP conflict message, but the workstation would still be able to send and receive some traffic, and other devices on the network would also experience issues. This does not explain a total lack of connectivity.
- ✗
The Ethernet cable is faulty
Why it's wrong here
A faulty cable cannot produce solid link lights on both the NIC and switch port, and it would not selectively block traffic while other workstations on the same switch work normally. It is tempting because cabling is the usual suspect for no connectivity, but the link state and static-IP failure point elsewhere.
- ✗
The DHCP server has exhausted its IP address pool
Why it's wrong here
DHCP pool exhaustion would block dynamic addressing, yet a manually assigned static address in the correct subnet should still reach the gateway. It is tempting because the initial DHCP failure fits, but the static test rules it out; the fault lies in the path or port, not address availability.
Visual reference
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
One of 896 original 220-1101 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on 220-1101
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A user connects a laptop to a hotel's wired Ethernet port. The laptop obtains an IP address of 169.254.15.32 and cannot access the internet. Other guests' laptops on the same hotel network work without issue. The technician has verified that the laptop's network adapter is enabled, the driver is up to date, and that the Ethernet cable is securely connected. Which of the following is the MOST likely cause of the issue?
medium- A.The hotel's DHCP server is down
- B.The DNS server address is unreachable
- C.The Ethernet cable is faulty
- ✓ D.The switch port is configured with MAC address filtering
Why D: The IP address 169.254.15.32 is an Automatic Private IP Addressing (APIPA) address, assigned when a DHCP server is not reached. Since other guests' laptops work fine, the hotel's DHCP server is operational, ruling out a server-side issue. MAC address filtering on the switch port would block the laptop's DHCP request, causing it to fail to obtain a valid IP and fall back to APIPA, while other devices with allowed MAC addresses work normally.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1101 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1101 exam.