GSEC Defensible Network Architecture Practice Question
Exhibit
interface GigabitEthernet0/1 switchport mode access switchport access vlan 50 switchport port-security maximum 2 switchport port-security violation shutdown !
Refer to the exhibit. A network administrator configured port security on a switch interface to protect against unauthorized device connections. Based on the provided configuration snippet, what action will the switch take if a third device with an unknown MAC address connects to this port?
⚠ Common exam trap
Candidates often assume the switch will only block the third device. They forget that the 'shutdown' violation mode forces the entire port into an error-disabled state, stopping all traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The switch will immediately transition the interface into an error-disabled state and shut down port operations.
When port security is configured with a maximum limit of two MAC addresses and a violation mode of shutdown, the switch immediately disables the interface the moment a third unique MAC address attempts to communicate. The port enters an error-disabled state, dropping all traffic until an administrator manually resets the interface or configures an automatic recovery timer.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The switch will forward the third device's traffic while generating an alert log entry to the central syslog server without dropping packets.
Why it's wrong here
The restrict violation mode generates log entries and SNMP traps while dropping traffic from unauthorized devices, whereas the shutdown mode actively disables the port. The configured shutdown command explicitly mandates that the interface be transitioned to an error-disabled state.
- ✓
The switch will immediately transition the interface into an error-disabled state and shut down port operations.
Why this is correct
Configuring port security with violation shutdown instructs the switch to disable the interface immediately upon detecting more unique MAC addresses than permitted. This robust defense prevents unauthorized hardware from maintaining connectivity to the access network.
- ✗
The switch will drop packets originating from the third device while keeping the physical port in an active operational state.
Why it's wrong here
Dropping unauthorized packets while maintaining an active link represents the restrict violation mode. The configured shutdown mode goes further by entirely shutting down the physical interface to eliminate any further interaction from the unauthorized device.
- ✗
The switch will temporarily quarantine the third device in a restricted guest VLAN while awaiting administrator approval.
Why it's wrong here
Port security violation modes are shutdown, restrict and protect; none quarantines a device into a guest VLAN. It tempts because dynamic VLAN assignment via 802.1X or RADIUS does place unknown endpoints in a restricted VLAN, but that scenario requires authentication configuration, not the port-security snippet shown.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
About these practice questions
Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.