nerdexam
Cisco

300-320 · Question #45

A Layer 2 switch in the network has recently started broadcasting traffic out of every port and is impacting network performance. The engineering department determines that a MAC overflow attack is…

The correct answer is A. Storm Control B. Port Security. Port Security directly prevents MAC overflow attacks by limiting the number of MAC addresses allowed on a switchport. If the limit is exceeded, the port can shut down or drop traffic, stopping an attacker from flooding the CAM table. Storm Control mitigates the damage by…

Security Services

Question

A Layer 2 switch in the network has recently started broadcasting traffic out of every port and is impacting network performance. The engineering department determines that a MAC overflow attack is the cause. Which two features can protect and mitigate the damage of the attacks? (Choose two.)

Options

  • AStorm Control
  • BPort Security
  • CSPAN
  • DBPDU Filters
  • EIP Source Guard
  • FVACLs

How the community answered

(54 responses)
  • A
    81% (44)
  • C
    6% (3)
  • D
    9% (5)
  • E
    2% (1)
  • F
    2% (1)

Explanation

Port Security directly prevents MAC overflow attacks by limiting the number of MAC addresses allowed on a switchport. If the limit is exceeded, the port can shut down or drop traffic, stopping an attacker from flooding the CAM table. Storm Control mitigates the damage by rate-limiting broadcast, multicast, and unknown unicast traffic - the type of traffic that floods when the CAM table overflows. SPAN is a traffic mirroring feature for analysis. BPDU Filter prevents STP BPDUs. IP Source Guard validates IP-to-MAC bindings. VACLs filter VLAN traffic but do not directly limit MAC flooding.

Topics

#MAC flooding#port security#storm control#Layer 2 security

Community Discussion

No community discussion yet for this question.

Full 300-320 Practice