Courseiva
Networking →easyMultiple Choice

MAC Address Filtering & Port Security — Troubleshooting No IP Address

A technician connects a new workstation to a wall jack in an office. The link lights on both the workstation's NIC and the switch port are solid green. The workstation cannot obtain an IP address via DHCP. The technician manually assigns a static IP address in the same subnet as other working workstations (192.168.1.100/24, gateway 192.168.1.1), but the workstation still cannot ping the gateway or any other device on the network. Other workstations connected to the same switch can access network resources normally. Which of the following is the MOST likely cause of this issue?

Quick Answer

The combination of details in this question is designed to guide you specifically toward a Layer 2 access control feature rather than a cabling, addressing, or DHCP problem. Solid link lights on both the workstation's NIC and the switch port confirm that the physical connection itself, Layer 1, is completely healthy, which rules out a bad cable or a faulty port. Yet the workstation cannot obtain an address via DHCP, and even manually assigning a valid static IP address in the correct subnet still fails to produce any connectivity at all, not even a ping to the gateway, while other workstations on that same switch work normally. A failure this total, affecting both automatic and manually configured addressing, while the physical link stays up, points to something actively filtering traffic based on identity rather than a configuration mistake, since a simple misconfiguration wouldn't typically block a correctly addressed static IP as well. Port security is designed to do exactly this: it restricts a switch port to specific authorized MAC addresses and blocks all traffic from anything else, regardless of whether that traffic is a DHCP request or already has a valid IP address. Whenever a device has a confirmed physical connection but cannot communicate at all, even after manually assigning correct addressing, and other devices on the same switch work fine, consider port security or another MAC-based filtering mechanism before continuing to troubleshoot addressing.

⚠ Common exam trap

The trap here is that candidates see solid link lights and assume Layer 1 is fully operational, forgetting that port security can block traffic at Layer 2 while keeping the port administratively up, leading them to incorrectly blame a faulty cable or IP conflict.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The switch port has port security enabled, and the workstation's MAC address is not allowed

The solid link lights indicate Layer 1 connectivity is good, ruling out a faulty cable. The inability to obtain an IP via DHCP and the failure to ping the gateway even with a manually assigned static IP in the correct subnet point to a Layer 2 filtering mechanism. Port security on the switch port is the most likely cause, as it would block all traffic from an unauthorized MAC address, preventing DHCP discovery and any subsequent communication, even with a valid static IP.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The switch port has port security enabled, and the workstation's MAC address is not allowed

    Why this is correct

    Port security restricts the switch port to specific permitted MAC addresses; an unlisted workstation's frames are dropped, so DHCP and static addressing both fail while other ports work. This matches the stem's symptom of solid link lights but no connectivity.

  • ✗

    The IP address 192.168.1.100 is already in use by another device

    Why it's wrong here

    A duplicate IP address would cause an IP conflict message, but the workstation would still be able to send and receive some traffic, and other devices on the network would also experience issues. This does not explain a total lack of connectivity.

  • ✗

    The Ethernet cable is faulty

    Why it's wrong here

    A faulty cable cannot produce solid link lights on both the NIC and switch port, and it would not selectively block traffic while other workstations on the same switch work normally. It is tempting because cabling is the usual suspect for no connectivity, but the link state and static-IP failure point elsewhere.

  • ✗

    The DHCP server has exhausted its IP address pool

    Why it's wrong here

    DHCP pool exhaustion would block dynamic addressing, yet a manually assigned static address in the correct subnet should still reach the gateway. It is tempting because the initial DHCP failure fits, but the static test rules it out; the fault lies in the path or port, not address availability.

Visual reference

Client DHCP Server 1 Discover (broadcast) 2 Offer (IP: 192.168.1.10) 3 Request (I accept) 4 Acknowledge (lease confirmed) DORA — the four-step DHCP lease process

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

One of 896 original 220-1101 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on 220-1101

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A user connects a laptop to a hotel's wired Ethernet port. The laptop obtains an IP address of 169.254.15.32 and cannot access the internet. Other guests' laptops on the same hotel network work without issue. The technician has verified that the laptop's network adapter is enabled, the driver is up to date, and that the Ethernet cable is securely connected. Which of the following is the MOST likely cause of the issue?

medium
  • A.The hotel's DHCP server is down
  • B.The DNS server address is unreachable
  • C.The Ethernet cable is faulty
  • ✓ D.The switch port is configured with MAC address filtering

Why D: The IP address 169.254.15.32 is an Automatic Private IP Addressing (APIPA) address, assigned when a DHCP server is not reached. Since other guests' laptops work fine, the hotel's DHCP server is operational, ruling out a server-side issue. MAC address filtering on the switch port would block the laptop's DHCP request, causing it to fail to obtain a valid IP and fall back to APIPA, while other devices with allowed MAC addresses work normally.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1101 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1101 exam.