Question 192 of 464
N10-009 Network Security Practice Question
A network administrator wants to prevent unauthorized devices from being plugged into switch ports. Only devices with specific MAC addresses should be allowed on each port. Which switch security feature should be enabled?
⚠ Common exam trap
CompTIA often tests the distinction between port security (MAC-based access control) and 802.1X (authentication-based access control), leading candidates to incorrectly choose 802.1X when the question explicitly mentions 'specific MAC addresses' rather than user credentials or certificates.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Port security
Port security is the correct feature because it allows the administrator to restrict which MAC addresses can communicate through a switch port. By configuring allowed MAC addresses (sticky or static), any device with an unknown MAC address attempting to send traffic will trigger a security violation (shutdown, restrict, or protect). This directly addresses the requirement to prevent unauthorized devices from being plugged into switch ports.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
DHCP snooping
Why it's wrong here
DHCP snooping is a Layer 2 security feature that filters untrusted DHCP messages to prevent rogue DHCP servers from issuing IP addresses and to build a DHCP snooping binding table. It marks switch ports as trusted or untrusted, allowing only DHCP server responses from trusted ports and dropping invalid DHCP messages from untrusted ports. While it protects the integrity of IP address assignment, DHCP snooping does not prevent an unauthorized device from physically connecting to a switch port or restrict its MAC address from attempting to communicate.
When this WOULD be correct
A network administrator wants to prevent rogue DHCP servers from offering IP addresses to clients on a specific VLAN. DHCP snooping should be enabled on the switch to filter DHCP messages and only allow DHCP responses from trusted ports.
- ✗
Dynamic ARP inspection
Why it's wrong here
Dynamic ARP Inspection (DAI) is a security feature designed to prevent ARP spoofing and poisoning attacks by validating ARP packets. It intercepts all ARP requests and replies on untrusted ports, comparing the source MAC address, source IP address, and destination IP address against a trusted binding database, often populated by DHCP snooping. While crucial for data plane integrity, DAI does not inherently restrict which physical devices can connect to a switch port; it only ensures the validity of ARP communications once a device is connected.
When this WOULD be correct
A network administrator wants to prevent man-in-the-middle attacks by ensuring that only valid ARP responses are accepted on a VLAN. DAI should be enabled to drop ARP packets with invalid IP-to-MAC address bindings.
- ✓
Port security
Why this is correct
Port security is a Layer 2 control mechanism configured on a switch port to restrict which MAC addresses are permitted to send traffic. It can be configured to allow only a specific number of MAC addresses, or even just one, to learn and communicate through that port. If an unauthorized device with a different MAC address attempts to connect, the port can be configured to shut down, restrict traffic, or simply drop packets from the unauthorized MAC, effectively preventing its use. This directly addresses the goal of preventing unauthorized devices from being plugged into a switch.
- ✗
802.1X
Why it's wrong here
IEEE 802.1X is a port-based network access control protocol that authenticates devices or users before granting them access to the network. It involves a supplicant (client), an authenticator (switch), and an authentication server (typically RADIUS) to verify credentials like usernames, passwords, or digital certificates. While 802.1X effectively prevents unauthorized devices from accessing network resources, it does not physically prevent a device from being plugged into a switch port; rather, it keeps the port in an unauthorized state until successful authentication occurs.
When this WOULD be correct
A question asks: 'A company wants to ensure that only authenticated users can connect to the network, using their domain credentials. Which switch security feature should be enabled?' In that scenario, 802.1X would be correct.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The N10-009 exam frequently reuses these exact scenarios with slightly different constraints.
✓Port securityCorrect answer▾
Why this is correct
Port security is a Layer 2 control mechanism configured on a switch port to restrict which MAC addresses are permitted to send traffic. It can be configured to allow only a specific number of MAC addresses, or even just one, to learn and communicate through that port. If an unauthorized device with a different MAC address attempts to connect, the port can be configured to shut down, restrict traffic, or simply drop packets from the unauthorized MAC, effectively preventing its use. This directly addresses the goal of preventing unauthorized devices from being plugged into a switch.
✗DHCP snoopingWrong answer — click to see why▾
Why this is wrong here
DHCP snooping is a security feature that filters untrusted DHCP messages and builds a DHCP snooping binding table, but it does not restrict which devices can be plugged into switch ports based on MAC addresses.
★ When this WOULD be the correct answer
A network administrator wants to prevent rogue DHCP servers from offering IP addresses to clients on a specific VLAN. DHCP snooping should be enabled on the switch to filter DHCP messages and only allow DHCP responses from trusted ports.
Why candidates choose this
Candidates may confuse DHCP snooping with port security because both involve MAC addresses; DHCP snooping tracks MAC-to-IP bindings, leading to the mistaken belief it can enforce MAC-based port access.
✗Dynamic ARP inspectionWrong answer — click to see why▾
Why this is wrong here
Dynamic ARP inspection (DAI) validates ARP packets to prevent ARP spoofing attacks, but it does not restrict which devices can be physically plugged into switch ports based on MAC addresses.
★ When this WOULD be the correct answer
A network administrator wants to prevent man-in-the-middle attacks by ensuring that only valid ARP responses are accepted on a VLAN. DAI should be enabled to drop ARP packets with invalid IP-to-MAC address bindings.
Why candidates choose this
Candidates may confuse DAI's use of MAC addresses for validation with port security's MAC address filtering, or think that any feature involving MAC addresses can restrict physical port access.
✗802.1XWrong answer — click to see why▾
Why this is wrong here
802.1X is a port-based network access control protocol that authenticates users or devices before granting network access, but it does not restrict specific MAC addresses per port; it relies on authentication credentials, not a static MAC address list.
★ When this WOULD be the correct answer
A question asks: 'A company wants to ensure that only authenticated users can connect to the network, using their domain credentials. Which switch security feature should be enabled?' In that scenario, 802.1X would be correct.
Why candidates choose this
Candidates may confuse MAC-based authentication (which 802.1X can use) with port security's static MAC address filtering, or think 802.1X can enforce MAC address lists when it typically uses RADIUS-based authentication.
Analysis generated from the official N10-009blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
About these practice questions
Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →
Last reviewed: Jun 30, 2026
This N10-009 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the N10-009 exam.
Question Discussion
Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.
Sign in to join the discussion.