📖 What is Port Security?

Port Security is a Layer 2 switch feature that limits the number of MAC addresses that can be learned on a specific physical port. It can be configured to shut down the port or drop traffic if an unauthorized device is connected.

🥋 Sensei Says:

"This is your primary defense against MAC flooding attacks. Be familiar with the 'violation' modes: shutdown, restrict, and protect."

📚 Certification: CompTIA Network+ Certification Exam (N10-009)

🔑 What are the Key Concepts of Port Security?

  • MAC Address Limits allow administrators to specify the maximum number of unique MAC addresses allowed on a port, preventing CAM table overflow attacks.
  • Sticky MAC addresses automatically learn the first device connected and save it to the running configuration, simplifying deployment while maintaining strict access control.
  • The Shutdown violation mode disables the port entirely upon a breach, requiring a manual administrator reset to restore connectivity to the network.
  • Restrict and Protect modes both drop unauthorized traffic, but Restrict generates an SNMP trap and logs the violation, whereas Protect drops traffic silently.
  • Port security primarily operates at Layer 2, serving as a critical defense against MAC flooding attacks that attempt to force switches into hub-like behavior.

🎯 How does Port Security appear on the N10-009 Exam?

A scenario might describe a network port that suddenly goes into an 'err-disabled' state after a user connects an unauthorized wireless router. You will be asked to identify the security feature and the specific violation mode being used.

You may be asked to recommend a configuration that prevents unauthorized devices from connecting to a port but ensures the administrator is notified via a log message whenever a violation occurs.

Expect questions where you must choose between static MAC entries and sticky MAC learning for a deployment involving hundreds of workstations to balance security with administrative overhead.

❓ Frequently Asked Questions

What is the main difference between Port Security and 802.1X?

Port Security relies on the MAC address, which can be spoofed, to control access. 802.1X is a more robust framework providing port-based authentication using credentials or certificates via a RADIUS server.


Why would I choose 'Restrict' over 'Protect' mode?

Use Restrict when you need visibility into security breaches. While both drop unauthorized packets, Restrict sends a notification to the management console, allowing admins to identify and respond to the intruder.


Can Port Security prevent all types of MAC spoofing?

No, Port Security cannot stop a sophisticated attacker from spoofing a known, authorized MAC address. It only prevents the connection of unknown MACs or too many MACs on a single port.

Related Terms from CompTIA Network+ Certification Exam

📝 Related Study Guides

Exam Tips 8 min read

CompTIA Network+ (N10-009): Exam Format, Domains & Tips

The CompTIA Network+ N10-009 exam contains up to 90 questions in 90 minutes, requiring 720 out of 900 to pass. It covers five domains: Networking Fundamentals (23%), Network Implementation (20%), Network Operations (18%), Network Security (19%), and Network Troubleshooting (20%). Expect multiple choice, multiple select, and performance-based questions testing hands-on networking skills.

Exam Tips 10 min read

CompTIA Network+ (N10-009): Exam Format, Domains & Tips

The CompTIA Network+ (N10-009) exam consists of a maximum of 90 questions, including multiple-choice and performance-based questions (PBQs), with a 90-minute time limit. To pass, you must master five core domains: Networking Fundamentals, Implementations, Operations, Security, and Troubleshooting, focusing heavily on real-world scenario application.

Exam Tips 10 min read

CompTIA Network+ (N10-009): What to Expect on the Exam

The CompTIA Network+ (N10-009) exam consists of a maximum of 90 questions, including multiple-choice and performance-based questions (PBQs), with a 90-minute time limit. You must master five core domains—Networking Fundamentals, Implementations, Operations, Security, and Troubleshooting—to achieve a passing score of 720 on a scale of 100-900.

🧠

Test Your Knowledge

Think you understand Port Security? Put it to the test with our practice exam.

Try 10 Free Questions

⭐ 1,000 expert-curated questions available with Premium

Upgrade Premium