Courseiva
Networking →mediumMultiple Choice

220-1101 Networking Practice Question

A small office network uses a managed switch with port security enabled. A new employee connects their laptop to a configured port, but the laptop cannot obtain an IP address or communicate on the network. The link light on the switch port is on. Other ports in the same VLAN work correctly. Which of the following is the MOST likely cause?

⚠ Common exam trap

CompTIA often tests the distinction between a port being administratively down (link light off) versus a port that is up but blocking traffic due to security features like port security (link light on but no data passes).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The switch port has MAC address filtering enabled that does not include the laptop's MAC

Port security with MAC address filtering restricts which devices can communicate through a switch port based on their MAC address. Since the link light is on (Layer 1 is up) but the laptop cannot obtain an IP address or communicate, the switch is likely dropping frames from the laptop's MAC because it is not in the allowed MAC list. This prevents DHCP discovery and all other traffic, even though the physical connection is established.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The switch port has MAC address filtering enabled that does not include the laptop's MAC

    Why this is correct

    When port security uses MAC address filtering, the switch examines the source MAC of every inbound frame and compares it against a configured allow list. The laptop's frame is dropped at the data-link layer, so DHCP discovers never reach the server and no IP is assigned, even though the physical link is up and the LED is lit. This creates the exact symptom of a working cable but complete network unresponsiveness.

  • ✗

    The switch port is administratively shut down

    Why it's wrong here

    Issuing the 'shutdown' command on an interface places it in administratively down state, which causes the switch to stop sending link pulses. With no link pulses, the laptop's NIC would not establish carrier, so the link light would remain off. Since the scenario states the link light is on, the port cannot be administratively shut down.

  • ✗

    The laptop has a static IP address that conflicts with another device

    Why it's wrong here

    An IP address conflict is a Layer 3 problem: the laptop first completes Ethernet link and DHCP (or uses a static address), then two devices claim the same IPv4 address. The conflict results in ARP instability and intermittent loss of connectivity, not a failure to obtain an address. If the laptop used a static IP, it would still have a configured address and would be able to send frames at the data-link layer, which is not what 'no network access' with an active link describes.

  • ✗

    The switch port is not in the correct VLAN

    Why it's wrong here

    Assigning the switchport to the wrong VLAN does not block the link; the physical and data-link layers remain active and the laptop can still send frames to other devices in that same VLAN. The problem would be limited to an inability to reach resources in other VLANs unless inter-VLAN routing is missing, but the laptop would normally still obtain DHCP if a DHCP server exists in its VLAN. Because the symptom is complete failure to communicate with anything, a port-security MAC filter is the more precise cause.

Visual reference

Client DHCP Server 1 Discover (broadcast) 2 Offer (IP: 192.168.1.10) 3 Request (I accept) 4 Acknowledge (lease confirmed) DORA — the four-step DHCP lease process

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

This 220-1101 question is part of Courseiva's 896-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 220-1101 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1101 exam.