nerdexam
Cisco

350-701 · Question #880

Refer to the exhibit. A network security engineer must enable and configure port security on a Cisco Catalyst switch. Up to 20 secure MAC addresses must be supported per port. In case of a…

The correct answer is A. switchport port-security violation restrict. In restrict mode, unknown-source packets are dropped while the MAC count exceeds the limit, and a syslog message (and violation counter increment) is generated, fulfilling both drop and logging requirements.

Submitted by asante_acc· Mar 30, 2026Secure Network Access, Visibility, and Enforcement

Question

Refer to the exhibit. A network security engineer must enable and configure port security on a Cisco Catalyst switch. Up to 20 secure MAC addresses must be supported per port. In case of a violation, packets from unknown sources must be dropped until the MAC address count drops below the threshold and a syslog message is logged. Which command completes the configuration?

Options

  • Aswitchport port-security violation restrict
  • Bswitchport port-security violation protect
  • Dswitchport port-security violation disable

How the community answered

(35 responses)
  • A
    77% (27)
  • B
    9% (3)
  • D
    14% (5)

Explanation

In restrict mode, unknown-source packets are dropped while the MAC count exceeds the limit, and a syslog message (and violation counter increment) is generated, fulfilling both drop and logging requirements.

Topics

#port security#MAC address limit#violation mode restrict#switch hardening

Community Discussion

No community discussion yet for this question.

Full 350-701 Practice