nerdexam
Cisco

350-701 · Question #738

Refer to the exhibit. Network access control is implemented on the LAN and an engineer must now configure the switch port level so that users with new corporate devices can connect to the corporate…

The correct answer is D. authentication violation replace. When network access control is implemented, configuring the switch port with authentication violation replace ensures new corporate devices can connect by replacing any existing authenticated session.

Submitted by yasin.bd· Mar 30, 2026Endpoint Security and Secure Network Access

Question

Refer to the exhibit. Network access control is implemented on the LAN and an engineer must now configure the switch port level so that users with new corporate devices can connect to the corporate LAN without issues. What must be configured next?

Options

  • Aclear port-security dynamic
  • Bshut and no shut
  • Cerrdisable recovery cause psesecure-violation
  • Dauthentication violation replace

How the community answered

(37 responses)
  • A
    14% (5)
  • B
    8% (3)
  • C
    5% (2)
  • D
    73% (27)

Why each option

When network access control is implemented, configuring the switch port with `authentication violation replace` ensures new corporate devices can connect by replacing any existing authenticated session.

Aclear port-security dynamic

`clear port-security dynamic` removes dynamically learned MAC addresses from port security, which is unrelated to the authentication behavior for new devices under NAC policies.

Bshut and no shut

`shut` and `no shut` administratively restart the interface, which can reset its state but does not configure the specific behavior for handling authentication violations when a new device connects.

Cerrdisable recovery cause psesecure-violation

`errdisable recovery cause port-security-violation` configures the switch to automatically recover a port that has been err-disabled due to a port security violation, but it does not change the initial violation action that might prevent new devices from connecting.

Dauthentication violation replaceCorrect

The `authentication violation replace` command configured on a switch port allows a new host to authenticate and gain network access even if the port already has an active authenticated session, effectively replacing the previous authentication. This is essential for preventing access issues for new corporate devices on NAC-enabled ports.

Concept tested: Network Access Control (NAC) port violation modes

Source: https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst3750x_3560x/software/release/12-2_55_se/configuration/guide/3750x_cg/sw_auth.html

Topics

#Cisco NAC#802.1X authentication#Switch port violation actions

Community Discussion

No community discussion yet for this question.

Full 350-701 Practice