HPE7-A06 · Question #81
For enhanced port security in an HPE network, which two configurations can prevent unauthorized devices from gaining access?
The correct answer is A. 802.1X with EAP-TLS C. MAC-based authentication. 802.1X with EAP-TLS (A) authenticates devices using certificates before granting network access, ensuring only trusted endpoints can connect to a port. MAC-based authentication (C) controls access by validating a device's hardware address against an allowed list, blocking…
Question
For enhanced port security in an HPE network, which two configurations can prevent unauthorized devices from gaining access?
Options
- A802.1X with EAP-TLS
- BStatic IP addresses
- CMAC-based authentication
- DIGMP Snooping
How the community answered
(40 responses)- A93% (37)
- B5% (2)
- D3% (1)
Explanation
802.1X with EAP-TLS (A) authenticates devices using certificates before granting network access, ensuring only trusted endpoints can connect to a port. MAC-based authentication (C) controls access by validating a device's hardware address against an allowed list, blocking unregistered devices at the port level. Both methods actively verify device identity, which is the core requirement for port security.
Why the distractors are wrong:
- B (Static IP addresses) controls addressing, not access - a rogue device can simply use an allowed static IP without being stopped at the port.
- D (IGMP Snooping) manages multicast traffic efficiency on a switch; it has nothing to do with authenticating or blocking devices.
Memory tip: Think "authentication = access control" - any answer involving verifying who the device is (certificates via 802.1X/EAP-TLS, or MAC address via MAC-auth) is a port security mechanism. IP addressing and multicast management are network management tools, not access gatekeepers.
Topics
Community Discussion
No community discussion yet for this question.