PrepAway - Latest Free Exam Questions & Answers

What is a valid reason for a switch to deny port access to new devices when port security is enabled?

What is a valid reason for a switch to deny port access to new devices when port security is enabled?

PrepAway - Latest Free Exam Questions & Answers

A.
The denied MAC addresses have already been learned or configured on another secure interface in the same VLAN.

B.
The denied MAC addresses are statically configured on the port.

C.
The minimum MAC threshold has been reached.

D.
The absolute aging times for the denied MAC addresses have expired.

3 Comments on “What is a valid reason for a switch to deny port access to new devices when port security is enabled?

  1. James Bond says:

    Answer: A

    Explanation

    A security violation occurs in either of these situations:

    * When the maximum number of secure MAC addresses is reached on a secure port and the source MAC address of the ingress traffic is different from any of the identified secure MAC addresses, port security applies the configured violation mode.

    * If traffic with a secure MAC address that is configured or learned on one secure port attempts to access another secure port in the same VLAN, applies the configured violation mode.

    From the second statement we can figure out A is the correct answer. But for your information we will discuss other answers as well.

    Answer B is not correct because we can’t configured which MAC address will be denied. We can only configure which MAC is allowed.

    We can only configure the maximum MAC threshold, not the minimum threshold -> C is not correct.

    The aging times are only configured for allowed MAC addresses, not for denied MAC -> D is correct.

    For your information about aging time:

    When the aging type is configured with the absolute keyword, all the dynamically learned secure addresses age out when the aging time expires

    This is how to configure the secure MAC address aging type on the port:

    Router(config-if)# switchport port-security aging type absolute

    and configure the aging time (aging time = 120 minutes)

    Router(config-if)# switchport port-security aging time 120

    When this command is used, all the dynamically learned secure addresses age out when the aging time expires

    (Reference: http://www.cisco.com/en/US/docs/switches/lan/catalyst6500/ios/12.2SX/configuration/guide/port_sec.html)




    0



    0

Leave a Reply