nerdexam
Cisco

350-601 · Question #672

Refer to the exhibit. A network engineer must configure the network to disable an interface when it exceeds the limit of learned MAC addresses. Which action accomplishes this goal?

The correct answer is B. Configure port security on interface Po100. Port security is the Cisco feature that limits the number of MAC addresses learned on an interface and can take action (restrict, protect, or shutdown) when that limit is exceeded. The 'shutdown' violation mode disables the interface entirely when the limit is breached. In the…

Security

Question

Refer to the exhibit. A network engineer must configure the network to disable an interface when it exceeds the limit of learned MAC addresses. Which action accomplishes this goal?

Exhibit

350-601 question #672 exhibit

Options

  • AConfigure port security on interface Po200.
  • BConfigure port security on interface Po100.
  • CConfigure Dynamic ARP inspection on interface Po200.
  • DConfigure Dynamic ARP inspection on interface Po100.

How the community answered

(36 responses)
  • A
    11% (4)
  • B
    81% (29)
  • C
    3% (1)
  • D
    6% (2)

Explanation

Port security is the Cisco feature that limits the number of MAC addresses learned on an interface and can take action (restrict, protect, or shutdown) when that limit is exceeded. The 'shutdown' violation mode disables the interface entirely when the limit is breached. In the exhibit, Po100 is the relevant access-facing port channel where the MAC address limit enforcement is needed. Dynamic ARP Inspection (DAI) is not the right tool here - it validates ARP packets to prevent spoofing but does not enforce MAC address count limits. Po200 is not the correct interface based on the topology shown.

Topics

#Port Security#MAC Address Limiting#Layer 2 Security#Interface Configuration

Community Discussion

No community discussion yet for this question.

Full 350-601 Practice