N10-009 Network Security Practice Question
A security auditor discovers that several unused switch ports are in default configuration. The auditor recommends implementing a security measure that will disable the port if an unauthorized device is connected, and then automatically re-enable the port after a specified time period. Which feature should be configured on the switch ports?
⚠ Common exam trap
The N10-009 exam often tests the distinction between port security's 'shutdown' violation mode (which triggers errdisable) and 'restrict' or 'protect' modes (which do not disable the port), leading candidates to incorrectly assume any port security mode meets the requirement for automatic re-enablement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Port security with violation mode 'shutdown' and errdisable recovery interval
Port security with violation mode 'shutdown' disables the port when an unauthorized device is detected, and the errdisable recovery interval automatically re-enables the port after a specified time period. This directly matches the auditor's requirement to disable on unauthorized connection and auto-re-enable after a timeout.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
802.1X with RADIUS authentication and guest VLAN
Why it's wrong here
802.1X is an authentication protocol that requires devices to authenticate with a RADIUS server before gaining network access. If a device fails authentication or is unauthorized, it can be placed into a restricted guest VLAN, providing limited network access, or be completely denied access. While it controls access, 802.1X typically does not shut down the port entirely in the same manner as port security's 'shutdown' mode, nor does it inherently include a time-based automatic re-enablement feature for the port itself, as its focus is on authentication state.
When this WOULD be correct
This option would be correct in a scenario requiring network access control where unauthorized devices should be placed in a restricted VLAN (guest VLAN) rather than having the port disabled. For example: 'A company wants to allow guests internet-only access while blocking internal resources, using RADIUS authentication.'
- ✓
Port security with violation mode 'shutdown' and errdisable recovery interval
Why this is correct
Port security configured with a 'shutdown' violation mode immediately disables a switch port upon detecting an unauthorized MAC address or exceeding the configured MAC address limit. This action places the port into an errdisable state, effectively preventing any further traffic. The `errdisable recovery interval` command then allows the port to automatically re-enable itself after a specified duration, making it available again for legitimate connections without manual intervention. This combination directly addresses the scenario of disabling unused ports and allowing for eventual re-use.
- ✗
DHCP snooping and dynamic ARP inspection
Why it's wrong here
DHCP snooping is a security feature that filters untrusted DHCP messages and builds a binding table to prevent rogue DHCP servers and spoofing. Dynamic ARP Inspection (DAI) leverages this binding table to validate ARP packets, preventing ARP poisoning attacks by dropping invalid ARP requests and replies. While crucial for data plane security, neither DHCP snooping nor DAI are designed to disable a switch port when an unauthorized device initially connects, nor do they offer an automatic recovery mechanism for port re-enablement.
When this WOULD be correct
A question asking for a feature that prevents DHCP starvation attacks and ARP spoofing by filtering DHCP messages and validating ARP packets on untrusted ports would make DHCP snooping and DAI the correct answer.
- ✗
Storm control and broadcast suppression
Why it's wrong here
Storm control and broadcast suppression are network features designed to prevent excessive broadcast, multicast, or unknown unicast traffic from overwhelming a switch and degrading network performance. While they mitigate network congestion caused by misbehaving devices or loops, they do not detect or prevent unauthorized devices from connecting to a port. These mechanisms operate on traffic thresholds, not on the identity or authorization status of connected endpoints.
When this WOULD be correct
A question asking: 'Which feature should be configured to prevent a broadcast storm from overwhelming a switch port?' would make storm control the correct answer, as it limits the rate of incoming broadcast traffic.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The N10-009 exam frequently reuses these exact scenarios with slightly different constraints.
✓Port security with violation mode 'shutdown' and errdisable recovery intervalCorrect answer▾
Why this is correct
Port security configured with a 'shutdown' violation mode immediately disables a switch port upon detecting an unauthorized MAC address or exceeding the configured MAC address limit. This action places the port into an errdisable state, effectively preventing any further traffic. The `errdisable recovery interval` command then allows the port to automatically re-enable itself after a specified duration, making it available again for legitimate connections without manual intervention. This combination directly addresses the scenario of disabling unused ports and allowing for eventual re-use.
✗802.1X with RADIUS authentication and guest VLANWrong answer — click to see why▾
Why this is wrong here
802.1X with RADIUS authentication and guest VLAN does not automatically disable a port upon unauthorized connection; it grants limited access via guest VLAN. It also does not automatically re-enable the port after a timeout, as errdisable recovery is specific to port security violation modes.
★ When this WOULD be the correct answer
This option would be correct in a scenario requiring network access control where unauthorized devices should be placed in a restricted VLAN (guest VLAN) rather than having the port disabled. For example: 'A company wants to allow guests internet-only access while blocking internal resources, using RADIUS authentication.'
Why candidates choose this
Candidates may confuse 802.1X with port security because both deal with unauthorized device access, and the guest VLAN concept seems similar to disabling the port. They overlook that 802.1X does not physically disable the port or provide automatic re-enablement.
✗DHCP snooping and dynamic ARP inspectionWrong answer — click to see why▾
Why this is wrong here
DHCP snooping and dynamic ARP inspection are security features that prevent DHCP spoofing and ARP poisoning attacks, but they do not disable ports upon unauthorized device connection or automatically re-enable them after a timeout.
★ When this WOULD be the correct answer
A question asking for a feature that prevents DHCP starvation attacks and ARP spoofing by filtering DHCP messages and validating ARP packets on untrusted ports would make DHCP snooping and DAI the correct answer.
Why candidates choose this
Candidates may confuse the port disabling behavior with the concept of 'shutdown' in DHCP snooping (which shuts down ports with DHCP attacks) or mistakenly think DAI can disable ports, but neither provides the automatic re-enablement described.
✗Storm control and broadcast suppressionWrong answer — click to see why▾
Why this is wrong here
Storm control and broadcast suppression are used to limit excessive broadcast, multicast, or unicast traffic to prevent network storms, not to disable ports upon unauthorized device connection or to automatically re-enable them after a timeout.
★ When this WOULD be the correct answer
A question asking: 'Which feature should be configured to prevent a broadcast storm from overwhelming a switch port?' would make storm control the correct answer, as it limits the rate of incoming broadcast traffic.
Why candidates choose this
Candidates may confuse 'storm control' with a security feature that reacts to unauthorized devices, or they might think that disabling a port due to a storm is similar to disabling it due to a security violation.
Analysis generated from the official N10-009blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Network Device Hardening
Key term
Switch
A switch is a networking device that connects devices on a local area network and uses MAC addresses to forward data only to the intended recipient.
Key term
Violation mode
Violation mode is a port security feature on Cisco switches that defines what action is taken when an unauthorized device attempts to connect to a secured switch port.
About these practice questions
Courseiva writes every N10-009 question from scratch — 464 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This N10-009 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the N10-009 exam.