exam questions

Exam 200-301 All Questions

View all questions & answers for the 200-301 exam

Exam 200-301 topic 1 question 642 discussion

Actual exam question from Cisco's 200-301
Question #: 642
Topic #: 1
[All 200-301 Questions]

A port security violation has occurred on a switch port due to the maximum MAC address count being exceeded. Which command must be configured to increment the security-violation count and forward an SNMP trap?

  • A. switchport port-security violation access
  • B. switchport port-security violation protect
  • C. switchport port-security violation restrict
  • D. switchport port-security violation shutdown
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
highfivejohn
Highly Voted 2 years, 6 months ago
Selected Answer: C
C is best answer, had the question included the port err-disabled then D
upvoted 10 times
...
dave1992
Highly Voted 3 years, 6 months ago
Protect - drops the packet with unknown src address until you remove a secure mac address to drop below the max value. no trap is sent. Restrict- same but violation increments and TRAP sent to SNMP manager. shutdown- puts interface in error disabled and sends a trap to the manager
upvoted 8 times
sgashashf
3 years, 2 months ago
When a port configured for "shutdown" experiences a violation, it sends an syslog message, sets the violation count to 1, then error disables. These questions are flat out wrong.
upvoted 1 times
...
...
yousrasebb
Most Recent 10 months, 3 weeks ago
here the key word is increment in the violation mode shutdown the counter is set to 1 not increment to 1 so for the voiloation mode restrict counter is increment by 1 for each traffic unauthorized
upvoted 2 times
...
[Removed]
1 year, 1 month ago
Selected Answer: C
C is correct
upvoted 1 times
...
[Removed]
1 year, 10 months ago
Selected Answer: C
C. switchport port-security violation restrict "restrict" will increment the security-violation count and forward an SNMP trap
upvoted 1 times
...
AlvinSK0814
2 years, 5 months ago
Answer should be D restrict—When the number of secure MAC addresses reaches the limit allowed on the port, packets with unknown source addresses are dropped until you remove a sufficient number of secure MAC addresses or increase the number of maximum allowable addresses. An SNMP trap is sent, a syslog message is logged, and the violation counter increments. shutdown—The interface is error-disabled when a violation occurs, and the port LED turns off. An SNMP trap is sent, a syslog message is logged, and the violation counter increments.
upvoted 2 times
RougePotatoe
2 years, 5 months ago
The question didn't say anything about the port being shut down what makes you so sure it's D?
upvoted 6 times
...
...
creaguy
2 years, 7 months ago
Selected Answer: D
Directly from the pdf provided reference. When configuring port security violation modes, note the following information: • protect—Drops packets with unknown source addresses until you remove a sufficient number of secure MAC addresses to drop below the maximum value. • restrict—Drops packets with unknown source addresses until you remove a sufficient number of secure MAC addresses to drop below the maximum value and causes the SecurityViolation counter to increment. • shutdown—Puts the interface into the error-disabled state immediately and sends an SNMP trap notification.
upvoted 2 times
splashy
2 years, 5 months ago
copy pasted directly out of provided link •Restrict—A port security violation restricts data, causes the SecurityViolation counter to increment, and causes an SNMP Notification to be generated. The rate at which SNMP traps are generated can be controlled by the snmp-server enable traps port-security trap-rate command. The default value ("0") causes an SNMP trap to be generated for every security violation. •Shutdown—A port security violation causes the interface to shut down immediately. When a secure port is in the error-disabled state, you can bring it out of this state by entering the errdisable recovery cause psecure-violation global configuration command or you can manually reenable it by entering the shutdown and no shut down interface configuration commands. This is the default mode.
upvoted 4 times
...
...
swampfartz
3 years ago
The question never states that they want the port shutdown as well. Therefore the best answer it C.
upvoted 4 times
...
DaBest
3 years, 6 months ago
C is correct, only Restrict will send a syslog/SNMP by default
upvoted 3 times
Chupacabro
3 years, 4 months ago
"Regarding the two correct answers, a port in port security restrict does cause the switch to issue log messages for a violating frame, send SNMP traps about that same event (if SNMP is configured), and increment the counter of violating frames." - CCNA 200-301 Vol. 2 by W. Odom So I assume that D is also an answer(only based on the book) as it also sends syslog and SNMP (if configured). But I guess it's a matter of specificity of perks unlocked, so also C for me.
upvoted 3 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago