Courseiva
Network Security →mediumMultiple Choice

N10-009 Network Security Practice Question

A network administrator wants to prevent unauthorized devices from connecting to the network through a switch port. Which security feature should be enabled on the switch?

⚠ Common exam trap

Test-takers frequently confuse port security or MAC filtering with true authentication, but the key point is that 802.1X is the only feature that performs per-device authentication against a central server, not just static MAC-based controls.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

802.1X

802.1X is the correct answer because it provides port-based network access control (PNAC) that authenticates devices before granting network access. It uses the Extensible Authentication Protocol (EAP) over LAN (EAPoL) to communicate with a RADIUS server, ensuring only authorized users or devices can connect through the switch port. This prevents unauthorized devices from accessing the network at Layer 2, regardless of MAC address or IP configuration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    802.1X

    Why this is correct

    802.1X authenticates devices before allowing them to send traffic, providing strong access control.

  • ✗

    Port security

    Why it's wrong here

    Port security restricts the number of allowed MAC addresses but does not authenticate the device; it can be bypassed with MAC spoofing.

    When this WOULD be correct

    A question asking 'Which feature prevents MAC flooding attacks by limiting the number of MAC addresses on a port?' would make port security the correct answer.

  • ✗

    MAC filtering

    Why it's wrong here

    MAC filtering simply allows or denies traffic based on MAC addresses and is not a strong authentication mechanism.

    When this WOULD be correct

    A network administrator wants to restrict network access to only devices with known MAC addresses on a small, static network without user authentication requirements.

  • ✗

    Storm control

    Why it's wrong here

    Storm control limits broadcast, multicast, or unknown unicast traffic to prevent denial of service, not unauthorized access.

    When this WOULD be correct

    A network administrator wants to prevent a broadcast storm from overwhelming the network. Which feature should be enabled on the switch?

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The N10-009 exam frequently reuses these exact scenarios with slightly different constraints.

✓802.1XCorrect answer▾

Why this is correct

802.1X authenticates devices before allowing them to send traffic, providing strong access control.

✗Port securityWrong answer — click to see why▾

Why this is wrong here

Port security limits the number of MAC addresses per port but does not authenticate devices; it can be bypassed by spoofing a learned MAC address.

★ When this WOULD be the correct answer

A question asking 'Which feature prevents MAC flooding attacks by limiting the number of MAC addresses on a port?' would make port security the correct answer.

Why candidates choose this

Candidates often confuse port security with device authentication because both control access based on MAC addresses, but port security lacks the authentication mechanism that 802.1X provides.

✗MAC filteringWrong answer — click to see why▾

Why this is wrong here

MAC filtering controls access based on MAC addresses but does not authenticate users or devices dynamically; it can be bypassed by MAC spoofing and does not integrate with authentication servers like RADIUS.

★ When this WOULD be the correct answer

A network administrator wants to restrict network access to only devices with known MAC addresses on a small, static network without user authentication requirements.

Why candidates choose this

Candidates confuse MAC filtering with port-based authentication, assuming that filtering MAC addresses is sufficient to prevent unauthorized devices, but it lacks the dynamic authentication and encryption of 802.1X.

✗Storm controlWrong answer — click to see why▾

Why this is wrong here

Storm control is used to limit broadcast, multicast, or unknown unicast traffic to prevent network storms, not to prevent unauthorized devices from connecting to a switch port.

★ When this WOULD be the correct answer

A network administrator wants to prevent a broadcast storm from overwhelming the network. Which feature should be enabled on the switch?

Why candidates choose this

Candidates may confuse 'storm control' with controlling access or security, thinking it prevents unauthorized traffic, but it actually manages traffic volume, not device authentication.

Analysis generated from the official N10-009blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

This N10-009 question is part of Courseiva's 472-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on N10-009

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A network administrator needs to ensure that only authorized devices can connect to the wired network. Each user must authenticate using their domain credentials. Which of the following should be implemented?

hard
  • A.MAC filtering
  • ✓ B.802.1X with EAP-TLS
  • C.WPA2-PSK
  • D.Port security

Why B: 802.1X with EAP-TLS is correct because it provides port-based network access control that requires each user to authenticate using their domain credentials (via a RADIUS server) before the switch port is opened for traffic. EAP-TLS uses mutual authentication with digital certificates, ensuring only authorized devices and users gain access to the wired network.

Variation 2. A network administrator wants to prevent unauthorized devices from connecting to the company's Ethernet ports. The company uses a centralized authentication server. Which IEEE standard should be implemented?

medium
  • ✓ A.802.1X
  • B.802.11i
  • C.802.3af
  • D.802.1Q

Why A: 802.1X is the IEEE standard for port-based Network Access Control (NAC) that authenticates devices before granting access to an Ethernet port. It uses a centralized authentication server (typically RADIUS) to verify credentials, preventing unauthorized devices from connecting to the network. This directly matches the requirement of controlling access at the port level with a centralized server.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This N10-009 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the N10-009 exam.