Courseiva

GSEC Defensible Network Architecture Practice Question

Exhibit

interface GigabitEthernet0/1
 switchport mode access
 switchport access vlan 50
 switchport port-security maximum 2
 switchport port-security violation shutdown
!

Refer to the exhibit. A network administrator configured port security on a switch interface to protect against unauthorized device connections. Based on the provided configuration snippet, what action will the switch take if a third device with an unknown MAC address connects to this port?

⚠ Common exam trap

Candidates often assume the switch will only block the third device. They forget that the 'shutdown' violation mode forces the entire port into an error-disabled state, stopping all traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The switch will immediately transition the interface into an error-disabled state and shut down port operations.

When port security is configured with a maximum limit of two MAC addresses and a violation mode of shutdown, the switch immediately disables the interface the moment a third unique MAC address attempts to communicate. The port enters an error-disabled state, dropping all traffic until an administrator manually resets the interface or configures an automatic recovery timer.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The switch will forward the third device's traffic while generating an alert log entry to the central syslog server without dropping packets.

    Why it's wrong here

    The restrict violation mode generates log entries and SNMP traps while dropping traffic from unauthorized devices, whereas the shutdown mode actively disables the port. The configured shutdown command explicitly mandates that the interface be transitioned to an error-disabled state.

  • ✓

    The switch will immediately transition the interface into an error-disabled state and shut down port operations.

    Why this is correct

    Configuring port security with violation shutdown instructs the switch to disable the interface immediately upon detecting more unique MAC addresses than permitted. This robust defense prevents unauthorized hardware from maintaining connectivity to the access network.

  • ✗

    The switch will drop packets originating from the third device while keeping the physical port in an active operational state.

    Why it's wrong here

    Dropping unauthorized packets while maintaining an active link represents the restrict violation mode. The configured shutdown mode goes further by entirely shutting down the physical interface to eliminate any further interaction from the unauthorized device.

  • ✗

    The switch will temporarily quarantine the third device in a restricted guest VLAN while awaiting administrator approval.

    Why it's wrong here

    Port security violation modes are shutdown, restrict and protect; none quarantines a device into a guest VLAN. It tempts because dynamic VLAN assignment via 802.1X or RADIUS does place unknown endpoints in a restricted VLAN, but that scenario requires authentication configuration, not the port-security snippet shown.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.