N10-009 Network Security Practice Question
A network administrator wants to prevent unauthorized devices from connecting to the network through a switch port. Which security feature should be enabled on the switch?
⚠ Common exam trap
Test-takers frequently confuse port security or MAC filtering with true authentication, but the key point is that 802.1X is the only feature that performs per-device authentication against a central server, not just static MAC-based controls.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
802.1X
802.1X is the correct answer because it provides port-based network access control (PNAC) that authenticates devices before granting network access. It uses the Extensible Authentication Protocol (EAP) over LAN (EAPoL) to communicate with a RADIUS server, ensuring only authorized users or devices can connect through the switch port. This prevents unauthorized devices from accessing the network at Layer 2, regardless of MAC address or IP configuration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
802.1X
Why this is correct
802.1X authenticates devices before allowing them to send traffic, providing strong access control.
- ✗
Port security
Why it's wrong here
Port security restricts the number of allowed MAC addresses but does not authenticate the device; it can be bypassed with MAC spoofing.
When this WOULD be correct
A question asking 'Which feature prevents MAC flooding attacks by limiting the number of MAC addresses on a port?' would make port security the correct answer.
- ✗
MAC filtering
Why it's wrong here
MAC filtering simply allows or denies traffic based on MAC addresses and is not a strong authentication mechanism.
When this WOULD be correct
A network administrator wants to restrict network access to only devices with known MAC addresses on a small, static network without user authentication requirements.
- ✗
Storm control
Why it's wrong here
Storm control limits broadcast, multicast, or unknown unicast traffic to prevent denial of service, not unauthorized access.
When this WOULD be correct
A network administrator wants to prevent a broadcast storm from overwhelming the network. Which feature should be enabled on the switch?
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The N10-009 exam frequently reuses these exact scenarios with slightly different constraints.
✓802.1XCorrect answer▾
Why this is correct
802.1X authenticates devices before allowing them to send traffic, providing strong access control.
✗Port securityWrong answer — click to see why▾
Why this is wrong here
Port security limits the number of MAC addresses per port but does not authenticate devices; it can be bypassed by spoofing a learned MAC address.
★ When this WOULD be the correct answer
A question asking 'Which feature prevents MAC flooding attacks by limiting the number of MAC addresses on a port?' would make port security the correct answer.
Why candidates choose this
Candidates often confuse port security with device authentication because both control access based on MAC addresses, but port security lacks the authentication mechanism that 802.1X provides.
✗MAC filteringWrong answer — click to see why▾
Why this is wrong here
MAC filtering controls access based on MAC addresses but does not authenticate users or devices dynamically; it can be bypassed by MAC spoofing and does not integrate with authentication servers like RADIUS.
★ When this WOULD be the correct answer
A network administrator wants to restrict network access to only devices with known MAC addresses on a small, static network without user authentication requirements.
Why candidates choose this
Candidates confuse MAC filtering with port-based authentication, assuming that filtering MAC addresses is sufficient to prevent unauthorized devices, but it lacks the dynamic authentication and encryption of 802.1X.
✗Storm controlWrong answer — click to see why▾
Why this is wrong here
Storm control is used to limit broadcast, multicast, or unknown unicast traffic to prevent network storms, not to prevent unauthorized devices from connecting to a switch port.
★ When this WOULD be the correct answer
A network administrator wants to prevent a broadcast storm from overwhelming the network. Which feature should be enabled on the switch?
Why candidates choose this
Candidates may confuse 'storm control' with controlling access or security, thinking it prevents unauthorized traffic, but it actually manages traffic volume, not device authentication.
Analysis generated from the official N10-009blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
WPA3 Protocol: SAE, Forward Secrecy
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
EAP
EAP is a flexible authentication framework used in network access control, supporting multiple methods like passwords, certificates, and tokens.
About these practice questions
This N10-009 question is part of Courseiva's 472-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on N10-009
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A network administrator needs to ensure that only authorized devices can connect to the wired network. Each user must authenticate using their domain credentials. Which of the following should be implemented?
hard- A.MAC filtering
- ✓ B.802.1X with EAP-TLS
- C.WPA2-PSK
- D.Port security
Why B: 802.1X with EAP-TLS is correct because it provides port-based network access control that requires each user to authenticate using their domain credentials (via a RADIUS server) before the switch port is opened for traffic. EAP-TLS uses mutual authentication with digital certificates, ensuring only authorized devices and users gain access to the wired network.
Variation 2. A network administrator wants to prevent unauthorized devices from connecting to the company's Ethernet ports. The company uses a centralized authentication server. Which IEEE standard should be implemented?
medium- ✓ A.802.1X
- B.802.11i
- C.802.3af
- D.802.1Q
Why A: 802.1X is the IEEE standard for port-based Network Access Control (NAC) that authenticates devices before granting access to an Ethernet port. It uses a centralized authentication server (typically RADIUS) to verify credentials, preventing unauthorized devices from connecting to the network. This directly matches the requirement of controlling access at the port level with a centralized server.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This N10-009 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the N10-009 exam.