N10-009 Network Security Practice Question
A security engineer is configuring port security on a switch to prevent unauthorized devices from connecting. The requirement is that only the first device to connect to a port is allowed, and if a different device connects, the port should be disabled. Which port security violation mode should be configured?
⚠ Common exam trap
The N10-009 exam often tests the distinction that 'shutdown' is the only mode that physically disables the port, while 'restrict' and 'protect' only filter traffic but leave the port administratively up, leading candidates to mistakenly choose 'restrict' because it logs violations.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Shutdown
The 'shutdown' violation mode disables the port entirely when a violation occurs, which meets the requirement that the port be disabled if a different device connects. This is the only mode that physically err-disables the port, preventing any further traffic until manually re-enabled.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Protect
Why it's wrong here
Protect mode silently discards traffic originating from unauthorized MAC addresses without disabling the port or generating any log messages or SNMP traps. While it prevents unauthorized data from traversing the network, the port remains active and no alert is raised, meaning administrators are not notified of the security violation. This lack of notification makes it less suitable for scenarios requiring active monitoring and immediate awareness of security breaches.
When this WOULD be correct
When the requirement is to silently drop traffic from unauthorized devices without generating alerts or disabling the port, such as in a low-security environment where only traffic filtering is needed.
- ✗
Restrict
Why it's wrong here
Restrict mode drops traffic from unauthorized MAC addresses and, unlike Protect mode, generates a log message or sends an SNMP trap to alert network administrators of the security violation. Although it provides notification and prevents unauthorized data flow, the switch port itself remains operational and does not shut down. This allows legitimate traffic from authorized MAC addresses to continue, but it may not be sufficient for environments demanding the complete isolation of a compromised port.
When this WOULD be correct
A question where the requirement is to log and alert on unauthorized access attempts without disrupting existing traffic, such as 'A security engineer wants to monitor for unauthorized devices on a port while allowing them to connect for auditing purposes. Which violation mode should be used?'
- ✓
Shutdown
Why this is correct
Shutdown mode is the most stringent port security violation action, immediately disabling the switch port upon detection of an unauthorized MAC address. This action effectively takes the port offline, preventing any further traffic flow and completely blocking unauthorized access attempts. Re-enabling the port typically requires manual intervention by an administrator, making it a highly secure but operationally impactful response that directly prevents unauthorized use.
- ✗
Sticky
Why it's wrong here
Sticky MAC address learning is a configuration method for port security, not a violation mode that dictates the action taken when a security breach occurs. This feature dynamically learns MAC addresses connected to a port and then saves them to the running configuration, effectively making them 'sticky' or persistent. However, it does not define whether the port should shut down, restrict, or protect traffic if an unknown MAC address attempts to connect; that action is determined by a separate violation mode setting.
When this WOULD be correct
A question asks: 'Which port security feature allows a switch to automatically learn and save MAC addresses to the running configuration to prevent unauthorized devices?' In that case, sticky learning would be the correct answer.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The N10-009 exam frequently reuses these exact scenarios with slightly different constraints.
✓ShutdownCorrect answer▾
Why this is correct
Shutdown mode is the most stringent port security violation action, immediately disabling the switch port upon detection of an unauthorized MAC address. This action effectively takes the port offline, preventing any further traffic flow and completely blocking unauthorized access attempts. Re-enabling the port typically requires manual intervention by an administrator, making it a highly secure but operationally impactful response that directly prevents unauthorized use.
✗ProtectWrong answer — click to see why▾
Why this is wrong here
The Protect mode drops traffic from unauthorized devices but does not disable the port, which contradicts the requirement that the port should be disabled when a different device connects.
★ When this WOULD be the correct answer
When the requirement is to silently drop traffic from unauthorized devices without generating alerts or disabling the port, such as in a low-security environment where only traffic filtering is needed.
Why candidates choose this
Candidates may confuse 'protect' with 'shutdown' because both involve preventing unauthorized access, but they overlook that protect does not disable the port.
✗RestrictWrong answer — click to see why▾
Why this is wrong here
Restrict mode allows traffic from unauthorized devices but logs the violation and increments a counter; it does not disable the port, which is required by the question's condition that the port be disabled when a different device connects.
★ When this WOULD be the correct answer
A question where the requirement is to log and alert on unauthorized access attempts without disrupting existing traffic, such as 'A security engineer wants to monitor for unauthorized devices on a port while allowing them to connect for auditing purposes. Which violation mode should be used?'
Why candidates choose this
Candidates may confuse 'restrict' with 'shutdown' because both respond to violations, but 'restrict' sounds like it would block access, whereas it actually only logs and allows traffic.
✗StickyWrong answer — click to see why▾
Why this is wrong here
Sticky is not a violation mode; it is a feature that dynamically learns MAC addresses and adds them to the running configuration. The question asks for a violation mode that disables the port when a different device connects, which is 'shutdown'.
★ When this WOULD be the correct answer
A question asks: 'Which port security feature allows a switch to automatically learn and save MAC addresses to the running configuration to prevent unauthorized devices?' In that case, sticky learning would be the correct answer.
Why candidates choose this
Candidates may confuse 'sticky' with a violation mode because it is often used in conjunction with port security to enforce MAC address limits, leading them to think it handles violations.
Analysis generated from the official N10-009blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Go deeper
Related to this question
Learn chapter
Network Device Hardening
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Switch
A switch is a networking device that connects devices on a local area network and uses MAC addresses to forward data only to the intended recipient.
About these practice questions
Courseiva writes every N10-009 question from scratch — 464 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This N10-009 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the N10-009 exam.