Courseiva

GSEC Defensible Network Architecture Practice Question

An organization is hardening its internal corporate network architecture to prevent unauthorized hosts from connecting to switch ports in common areas and conference rooms. Which TWO configurations should the network engineering team implement to achieve this security objective? (Choose TWO)

⚠ Common exam trap

Candidates often choose physical locks or basic password policies. These do not address the network-level requirement of controlling access to specific switch ports for unknown devices in public areas.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enabling 802.1X port-based authentication integrated with a RADIUS server and extensible authentication protocol.

Implementing 802.1X port-based authentication forces every connecting device to authenticate against a central directory service before gaining network access. Combined with port security limits that restrict the maximum number of registered MAC addresses per switch port, organizations effectively block rogue devices and unauthorized hardware from establishing unauthorized network connections in public areas.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enabling 802.1X port-based authentication integrated with a RADIUS server and extensible authentication protocol.

    Why this is correct

    802.1X port-based authentication requires every connecting client to provide valid credentials to an authentication server before the switch port transitions to an active state. This robust mechanism prevents unauthorized physical devices from accessing the internal network environment.

  • ✗

    Configuring static routing protocols on all access layer switches to bypass dynamic route poisoning attacks.

    Why it's wrong here

    Static routing configurations on access layer switches control network layer path selection rather than physical layer device authorization. This measure does nothing to prevent unauthorized physical hosts from plugging into vacant switch ports in public areas.

  • ✓

    Configuring switch port security to restrict the maximum number of dynamically learned MAC addresses per interface.

    Why this is correct

    Switch port security limits the quantity of unique MAC addresses allowed on a physical port. If an unauthorized device connects or if too many devices attach, the port immediately triggers a security violation action such as shutting down, thwarting unauthorized hardware.

  • ✗

    Deploying unmanaged network hubs in conference rooms to simplify physical cable management and port density.

    Why it's wrong here

    Unmanaged network hubs operate at Layer 1 and simply broadcast all incoming electrical signals to every port without filtering. Deploying hubs completely undermines network security by eliminating MAC address tracking and allowing promiscuous packet capture.

  • ✗

    Disabling spanning tree protocol root guard on all core enterprise switches to accelerate topology convergence times.

    Why it's wrong here

    Disabling spanning tree root guard removes a critical protection mechanism that prevents unauthorized switches from becoming the spanning tree root bridge. This misconfiguration invites denial of service conditions and traffic interception attacks across the switching fabric.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.