Port Security with Sticky MAC Addresses
A network technician is configuring a managed switch for a small office. The security requirement is that only specific authorized devices should be allowed to connect to the network via the switch ports. The technician wants to automatically learn the MAC addresses of devices as they connect and lock them to the port to prevent unauthorized devices from using the same port. Which switch feature should be configured to accomplish this?
Quick Answer
The answer is port security with sticky MAC addresses. This switch feature dynamically learns the MAC address of the first device connected to a port and then "sticks" that address to the port’s configuration, automatically locking it so that only that specific device can communicate through the port. If a different device attempts to connect, the switch will either block traffic or disable the port, depending on the violation mode set. On the CompTIA A+ Core 1 220-1101 exam, this concept tests your understanding of basic network security at Layer 2, often appearing in scenario-based questions about preventing unauthorized access in small offices. A common trap is confusing sticky MAC with static MAC entries—remember that sticky MAC automates the learning process, while static requires manual entry. Memory tip: think of "sticky" like a glue trap—once the first MAC sticks, no other device can get through.
⚠ Common exam trap
Candidates often confuse 'MAC filtering' (a static, manual ACL) with 'port security with sticky MAC' (which dynamically learns and locks addresses), leading them to choose A instead of B.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Port security with sticky MAC
Port security with sticky MAC addresses allows the switch to dynamically learn MAC addresses from connected devices and then 'stick' them to the port, preventing any other device from using that port. This meets the requirement of automatically learning and locking authorized devices without manual MAC entry.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
MAC filtering
Why it's wrong here
MAC filtering requires manually entering permitted addresses in an access list; it does not automatically learn connecting devices or lock them to a port. It is tempting because it also restricts access by MAC address, but the stem's automatic-learning requirement is satisfied by port security instead.
When this WOULD be correct
A network administrator needs to restrict network access to a list of pre-approved MAC addresses on a wireless access point. MAC filtering would be correct because it allows only those MACs to associate, without the need for port-based learning or locking.
- ✓
Port security with sticky MAC
Why this is correct
Sticky MAC learning dynamically records each device's MAC address into the running configuration and binds it to that port, satisfying the requirement to auto-learn and lock addresses. Any unauthorised device presenting a different MAC is then dropped, preventing port reuse.
- ✗
VLAN tagging (IEEE 802.1Q)
Why it's wrong here
802.1Q tags frames with VLAN identifiers to segment broadcast domains; it does not authenticate or restrict which MAC addresses may attach to a port. It is tempting because VLANs can isolate traffic, but the requirement is automatic MAC learning and locking, which port security provides.
When this WOULD be correct
A network technician needs to separate traffic from different departments (e.g., Sales, HR, IT) on the same switch to improve security and reduce broadcast traffic. The switch should support multiple VLANs and allow frames to carry VLAN identification across trunk links.
- ✗
Spanning Tree Protocol (STP)
Why it's wrong here
STP prevents network loops in redundant topologies; it does not provide port-level MAC address restrictions.
When this WOULD be correct
When a network has multiple switches connected in a loop and the requirement is to prevent broadcast storms and ensure a single active path between any two network nodes, STP would be the correct feature to configure.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The 220-1101 exam frequently reuses these exact scenarios with slightly different constraints.
✓Port security with sticky MACCorrect answer▾
Why this is correct
Sticky MAC learning dynamically records each device's MAC address into the running configuration and binds it to that port, satisfying the requirement to auto-learn and lock addresses. Any unauthorised device presenting a different MAC is then dropped, preventing port reuse.
✗MAC filteringWrong answer — click to see why▾
Why this is wrong here
MAC filtering only allows or denies traffic based on MAC addresses but does not automatically learn and lock addresses to a specific port; it requires manual configuration and does not prevent a different device from using the same port once the authorized MAC is removed.
★ When this WOULD be the correct answer
A network administrator needs to restrict network access to a list of pre-approved MAC addresses on a wireless access point. MAC filtering would be correct because it allows only those MACs to associate, without the need for port-based learning or locking.
Why candidates choose this
Candidates confuse MAC filtering with port security because both involve MAC addresses, but they overlook that port security with sticky MAC provides automatic learning and locking, whereas MAC filtering is static and not port-specific.
✗VLAN tagging (IEEE 802.1Q)Wrong answer — click to see why▾
Why this is wrong here
VLAN tagging (IEEE 802.1Q) is used to segregate network traffic into separate broadcast domains, not to restrict device access based on MAC addresses. It does not provide per-port MAC address locking or automatic learning of authorized devices.
★ When this WOULD be the correct answer
A network technician needs to separate traffic from different departments (e.g., Sales, HR, IT) on the same switch to improve security and reduce broadcast traffic. The switch should support multiple VLANs and allow frames to carry VLAN identification across trunk links.
Why candidates choose this
Candidates may confuse VLAN tagging with MAC-based security because both involve controlling network access, but VLAN tagging focuses on traffic segmentation rather than device authentication.
✗Spanning Tree Protocol (STP)Wrong answer — click to see why▾
Why this is wrong here
Spanning Tree Protocol (STP) prevents loops in redundant network topologies by blocking duplicate paths, not by restricting device access to switch ports based on MAC addresses.
★ When this WOULD be the correct answer
When a network has multiple switches connected in a loop and the requirement is to prevent broadcast storms and ensure a single active path between any two network nodes, STP would be the correct feature to configure.
Why candidates choose this
Candidates may confuse STP's role in managing port states (blocking/forwarding) with security-based port control, mistakenly thinking it can block unauthorized devices.
Analysis generated from the official 220-1101blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
One of 896 original 220-1101 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on 220-1101
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A network technician is configuring a managed switch for a small office. The security policy requires that only specific authorized devices should be allowed to connect to the network via the switch ports. The technician wants the switch to automatically learn the MAC addresses of the first device that connects to each port and then lock that port to only that MAC address. Any other device connecting to the same port should be blocked. Which switch feature should be configured to accomplish this?
medium- ✓ A.Port security with sticky MAC addresses.
- B.802.1X authentication.
- C.DHCP snooping.
- D.VLAN hopping prevention.
Why A: Port security with sticky MAC addresses allows the switch to dynamically learn the MAC address of the first device connected to a port and then 'stick' that address to the port's configuration. Once learned, the switch will block any other MAC address from communicating on that port, enforcing the security policy that only the authorized device can connect.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1101 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1101 exam.