exam questions

Exam 350-601 All Questions

View all questions & answers for the 350-601 exam

Exam 350-601 topic 1 question 258 discussion

Actual exam question from Cisco's 350-601
Question #: 258
Topic #: 1
[All 350-601 Questions]

Port security is statically configured on a Cisco Nexus 7700 Series switch and F3 line card. The switch is configured with an Advanced Services license. Which two actions delete secured MAC addresses from the interface? (Choose two.)

  • A. The address must be removed from the configuration.
  • B. Shutdown and then no shutdown must be run on the interface.
  • C. The device must be restarted manually.
  • D. The address must reach the age limit that is configured for the interface.
  • E. The interface must be converted to a routed port.
Show Suggested Answer Hide Answer
Suggested Answer: AE 🗳️
Removing a Static Secure MAC Address on an Interface:
You can remove a static secure MAC address on a Layer 2 interface.
Switched port to routed port:
When you change an interface from a Layer 2 interface to a Layer 3 interface, the device disables port security on the interface and discards all port security configuration for the interface. The device also discards all secure MAC addresses for the interface, regardless of the method used to learn the address.
Reference:
https://www.cisco.com/c/en/us/td/docs/switches/datacenter/sw/6_x/nx-os/security/configuration/guide/b_Cisco_Nexus_7000_NX-
OS_Security_Configuration_Guide__Release_6-x/b_Cisco_Nexus_7000_NX-OS_Security_Configuration_Guide__Release_6-x_chapter_010001.html

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
PassMan
Highly Voted 1 year, 10 months ago
A,E https://www.cisco.com/c/en/us/td/docs/switches/datacenter/sw/6_x/nx-os/security/configuration/guide/b_Cisco_Nexus_7000_NX-OS_Security_Configuration_Guide__Release_6-x/b_Cisco_Nexus_7000_NX-OS_Security_Configuration_Guide__Release_6-x_chapter_010001.html
upvoted 8 times
...
GuyThatTakesDumps
Most Recent 7 months, 3 weeks ago
Selected Answer: AE
A and E!
upvoted 2 times
...
Daeh
1 year, 10 months ago
B and E are correct. When you change an interface from a Layer 2 interface to a Layer 3 interface, the device disables port security on the interface and discards all port security configuration for the interface. The device also discards all secure MAC addresses for the interface, regardless of the method used to learn the address. Dynamic Learning is the default learning method. To remove all addresses learned by the dynamic method, use the shutdown and no shutdown commands to restart the interface. https://www.cisco.com/c/en/us/td/docs/switches/datacenter/sw/6_x/nx-os/security/configuration/guide/b_Cisco_Nexus_7000_NX-OS_Security_Configuration_Guide__Release_6-x/b_Cisco_Nexus_7000_NX-OS_Security_Configuration_Guide__Release_6-x_chapter_010001.html#steps_1131891-CLI
upvoted 1 times
malkovitch
1 year, 9 months ago
It's A and E. B is incorrect. The MAC address is not dynamically learned. Take a look at the question : "Port security is STATICALLY configured...".
upvoted 6 times
HN6366
1 year, 7 months ago
A static secure MAC address entry remains in the configuration of an interface until one of the following events occurs: You explicitly remove the address from the configuration. You configure the interface to act as a Layer 3 interface.
upvoted 4 times
...
...
...
GeekT
1 year, 10 months ago
Answer seems correct. https://www.cisco.com/c/en/us/td/docs/switches/datacenter/sw/6_x/nx-os/security/configuration/guide/b_Cisco_Nexus_7000_NX-OS_Security_Configuration_Guide__Release_6-x/b_Cisco_Nexus_7000_NX-OS_Security_Configuration_Guide__Release_6-x_chapter_010001.html
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...