Courseiva
Networking →mediumMultiple Choice

Port Security with Sticky MAC Addresses

A network technician is configuring a managed switch for a small office. The security requirement is that only specific authorized devices should be allowed to connect to the network via the switch ports. The technician wants to automatically learn the MAC addresses of devices as they connect and lock them to the port to prevent unauthorized devices from using the same port. Which switch feature should be configured to accomplish this?

Quick Answer

The answer is port security with sticky MAC addresses. This switch feature dynamically learns the MAC address of the first device connected to a port and then "sticks" that address to the port’s configuration, automatically locking it so that only that specific device can communicate through the port. If a different device attempts to connect, the switch will either block traffic or disable the port, depending on the violation mode set. On the CompTIA A+ Core 1 220-1101 exam, this concept tests your understanding of basic network security at Layer 2, often appearing in scenario-based questions about preventing unauthorized access in small offices. A common trap is confusing sticky MAC with static MAC entries—remember that sticky MAC automates the learning process, while static requires manual entry. Memory tip: think of "sticky" like a glue trap—once the first MAC sticks, no other device can get through.

⚠ Common exam trap

Candidates often confuse 'MAC filtering' (a static, manual ACL) with 'port security with sticky MAC' (which dynamically learns and locks addresses), leading them to choose A instead of B.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Port security with sticky MAC

Port security with sticky MAC addresses allows the switch to dynamically learn MAC addresses from connected devices and then 'stick' them to the port, preventing any other device from using that port. This meets the requirement of automatically learning and locking authorized devices without manual MAC entry.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    MAC filtering

    Why it's wrong here

    MAC filtering requires manually entering permitted addresses in an access list; it does not automatically learn connecting devices or lock them to a port. It is tempting because it also restricts access by MAC address, but the stem's automatic-learning requirement is satisfied by port security instead.

    When this WOULD be correct

    A network administrator needs to restrict network access to a list of pre-approved MAC addresses on a wireless access point. MAC filtering would be correct because it allows only those MACs to associate, without the need for port-based learning or locking.

  • ✓

    Port security with sticky MAC

    Why this is correct

    Sticky MAC learning dynamically records each device's MAC address into the running configuration and binds it to that port, satisfying the requirement to auto-learn and lock addresses. Any unauthorised device presenting a different MAC is then dropped, preventing port reuse.

  • ✗

    VLAN tagging (IEEE 802.1Q)

    Why it's wrong here

    802.1Q tags frames with VLAN identifiers to segment broadcast domains; it does not authenticate or restrict which MAC addresses may attach to a port. It is tempting because VLANs can isolate traffic, but the requirement is automatic MAC learning and locking, which port security provides.

    When this WOULD be correct

    A network technician needs to separate traffic from different departments (e.g., Sales, HR, IT) on the same switch to improve security and reduce broadcast traffic. The switch should support multiple VLANs and allow frames to carry VLAN identification across trunk links.

  • ✗

    Spanning Tree Protocol (STP)

    Why it's wrong here

    STP prevents network loops in redundant topologies; it does not provide port-level MAC address restrictions.

    When this WOULD be correct

    When a network has multiple switches connected in a loop and the requirement is to prevent broadcast storms and ensure a single active path between any two network nodes, STP would be the correct feature to configure.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The 220-1101 exam frequently reuses these exact scenarios with slightly different constraints.

✓Port security with sticky MACCorrect answer▾

Why this is correct

Sticky MAC learning dynamically records each device's MAC address into the running configuration and binds it to that port, satisfying the requirement to auto-learn and lock addresses. Any unauthorised device presenting a different MAC is then dropped, preventing port reuse.

✗MAC filteringWrong answer — click to see why▾

Why this is wrong here

MAC filtering only allows or denies traffic based on MAC addresses but does not automatically learn and lock addresses to a specific port; it requires manual configuration and does not prevent a different device from using the same port once the authorized MAC is removed.

★ When this WOULD be the correct answer

A network administrator needs to restrict network access to a list of pre-approved MAC addresses on a wireless access point. MAC filtering would be correct because it allows only those MACs to associate, without the need for port-based learning or locking.

Why candidates choose this

Candidates confuse MAC filtering with port security because both involve MAC addresses, but they overlook that port security with sticky MAC provides automatic learning and locking, whereas MAC filtering is static and not port-specific.

✗VLAN tagging (IEEE 802.1Q)Wrong answer — click to see why▾

Why this is wrong here

VLAN tagging (IEEE 802.1Q) is used to segregate network traffic into separate broadcast domains, not to restrict device access based on MAC addresses. It does not provide per-port MAC address locking or automatic learning of authorized devices.

★ When this WOULD be the correct answer

A network technician needs to separate traffic from different departments (e.g., Sales, HR, IT) on the same switch to improve security and reduce broadcast traffic. The switch should support multiple VLANs and allow frames to carry VLAN identification across trunk links.

Why candidates choose this

Candidates may confuse VLAN tagging with MAC-based security because both involve controlling network access, but VLAN tagging focuses on traffic segmentation rather than device authentication.

✗Spanning Tree Protocol (STP)Wrong answer — click to see why▾

Why this is wrong here

Spanning Tree Protocol (STP) prevents loops in redundant network topologies by blocking duplicate paths, not by restricting device access to switch ports based on MAC addresses.

★ When this WOULD be the correct answer

When a network has multiple switches connected in a loop and the requirement is to prevent broadcast storms and ensure a single active path between any two network nodes, STP would be the correct feature to configure.

Why candidates choose this

Candidates may confuse STP's role in managing port states (blocking/forwarding) with security-based port control, mistakenly thinking it can block unauthorized devices.

Analysis generated from the official 220-1101blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

One of 896 original 220-1101 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on 220-1101

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A network technician is configuring a managed switch for a small office. The security policy requires that only specific authorized devices should be allowed to connect to the network via the switch ports. The technician wants the switch to automatically learn the MAC addresses of the first device that connects to each port and then lock that port to only that MAC address. Any other device connecting to the same port should be blocked. Which switch feature should be configured to accomplish this?

medium
  • ✓ A.Port security with sticky MAC addresses.
  • B.802.1X authentication.
  • C.DHCP snooping.
  • D.VLAN hopping prevention.

Why A: Port security with sticky MAC addresses allows the switch to dynamically learn the MAC address of the first device connected to a port and then 'stick' that address to the port's configuration. Once learned, the switch will block any other MAC address from communicating on that port, enforcing the security policy that only the authorized device can connect.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1101 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1101 exam.