exam questions

Exam 200-301 All Questions

View all questions & answers for the 200-301 exam

Exam 200-301 topic 1 question 665 discussion

Actual exam question from Cisco's 200-301
Question #: 665
Topic #: 1
[All 200-301 Questions]

DRAG DROP -
An engineer is tasked to configure a switch with port security to ensure devices that forward unicasts, multicasts, and broadcasts are unable to flood the port. The port must be configured to permit only two random MAC addresses at a time. Drag and drop the required configuration commands from the left onto the sequence on the right. Not all commands are used.
Select and Place:

Show Suggested Answer Hide Answer
Suggested Answer:

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
THEKYPTONIAN
Highly Voted 2 years, 9 months ago
1.#switchport mode access 2.#switchport port-security 3.#switchport port-security maximum 2 4.#switch port-security sticky
upvoted 92 times
matass_md
9 months, 1 week ago
This is the right order , violation shutdown- this is the default option/behavior when you enable port security as mda2h said.
upvoted 1 times
...
mda2h
1 year, 9 months ago
Agreed! Default behavior is Shutdown mode. No need to specify it
upvoted 3 times
...
fransCISCO
2 years, 2 months ago
so this is the correct answer and sequence?? pls answer guys
upvoted 2 times
abdelkader163
1 year, 8 months ago
yes this is the correct order :))
upvoted 1 times
...
...
Elmasquentona963
1 year, 7 months ago
Yeah, that's the indicated order by "31-days-before-my-ccna".
upvoted 1 times
...
...
HeinyHo
Highly Voted 2 years, 7 months ago
It says: only two random MAC addresses at a time, not the first two macs. So the sticky command is incorrect, as are the static MACs, leaving only 4 options
upvoted 16 times
shaney67
1 year, 7 months ago
it says random MACs
upvoted 1 times
...
...
SeMo0o0o0o0
Most Recent 2 months, 3 weeks ago
WRONG switchport mode access switchport port-security switchport port-security maximum 2 switchport port-security violation shutdown keyword is randomly, not fixed, so we don´t need for sticky.
upvoted 2 times
...
Shaifalimittal02
6 months, 1 week ago
To configure port security in this scenario, you need to permit only two random MAC addresses at a time. The correct sequence of commands to achieve this is: switchport mode access This command sets the port to access mode, where port security can be applied. switchport port-security This enables port security on the port. switchport port-security maximum 2 This restricts the port to allow only two MAC addresses at a time. switchport port-security violation shutdown This command sets the violation mode to "shutdown," meaning if more than two MAC addresses are detected, the port will be shut down. Why not Sticky command is used:- The sticky command in port security is used to dynamically learn and retain the MAC addresses that are allowed on the port. If the requirement is to permit only two random MAC addresses at a time, the sticky command would not be necessary because it is primarily used for static environments where you want the port to remember and restrict the learned MAC addresses for future connections.
upvoted 2 times
...
Joshua25
6 months, 1 week ago
1. switchport mode access This is a must. The port must be in access mode for port security to work 2. switchport port-security Apparently a must. It enables the function. 3. switchport port-security maximum 2 This is a must as well, because the question specifically requires two addresses. 4. switchport port-security violation shutdown This is optional, but have to put here to make four answers. Why STICKY is wrong: The question requires "two random addresses at a time". If you use the sticky option, the first two address learned by the port will become permanent, and the port cannot accept new addresses. This is against "random". By contrast, without sticky, you can let old addresses age out, or re-enable the err-disabled port, and then the port can accept new addresses again, but still two maximum at any given time.
upvoted 1 times
Joshua25
6 months, 1 week ago
Please allow me explain more if you still don't understand why not STICKY. Two random addresses at a time = no sticky because, at A TIME, you allow random address XXX and YYY, at ANOTHER TIME, you may want to allow random address ZZZ and WWW, at A THIRD TIME, you may want to keep ZZZ but forget WWW and learn UUU. Auto recovery function can let the port forget old address and start accepting new addresses. Manually re-enable err-disabled port can let it start accepting new addresses. This meets the requirement of the question. Two random addresses in total throughout all the time = sticky because, once it has learned XXX and YYY, you never want it to learn ZZZ, WWW, UUU...
upvoted 1 times
...
...
[Removed]
1 year, 1 month ago
given answers are incorrect switchport mode access switchport port-security switchport port-security maximum 2 switch port-security sticky permit only two (random) MAC addresses at a time means that we shouldn´t use static MAC addresses. "switchport port-security violation shutdown" command is not needed here because the violation mode is shutdown by default.
upvoted 3 times
[Removed]
11 months, 3 weeks ago
after revision, i think that given answers are correct, sticky will make the MAC addresses fixed and the question says randomly two at a time, so the two must be able to change whenever.
upvoted 2 times
SeMo0o0o0o0
3 months, 1 week ago
it seems like the given answers have been changed. switchport mode access switchport port-security switchport port-security maximum 2 switchport port-security violation shutdown keyword is randomly, not fixed, so we don´t need for sticky.
upvoted 1 times
...
allyou
11 months, 2 weeks ago
1- switchport mode access 2-switchport port-security 3-switchport port-security maximum 2 4-switchport port-security violation shutdown Because with switch port-security sticky command MAC addresses are permanently fixed.
upvoted 2 times
...
...
...
Hayk__007
1 year, 7 months ago
Believe me) 1. #swithport mode access 2. #swithport port-security 3. #switchport port-security maximum 2 4. #switchport port-security violation shutdown Here we shouldn't use sticky mac addresses, as it's said that we need to use RANDOMLY addresses AT A TIME, so we don't any STATIC mac address, that we'll keep in our device(Sticky address keep the mac addresses in static form, we can check it with command #show mac-address table secure, and it will disapear if only we reload our device). Hence I'll be good with this 4 commands. Also the violation type is deffault shutdown, so it's definetly not the best command that Cisco can provide us, but the ones is false, so wee have not other choice.
upvoted 9 times
...
Elmasquentona963
1 year, 7 months ago
1st. Obviously the commands to configure static MAC addresses are discarded by condiition of the question. 2nd. And the "default" violation mode of a switch port with port security enabled = Shutdown (hence this option is not necessary). Finally, the correct order is: 1.#switchport mode access 2.#switchport port-security 3.#switchport port-security maximum 2 4.#switch port-security sticky
upvoted 2 times
...
dropspablo
1 year, 11 months ago
1.switchport mode access 2.switchport port-security 3.switchport port-security maximum 2 4.switchport port-security violation shutdown "Dynamic secure MAC addresses" are typically used when the host(s) connecting to a specific switchport is constantly changing, and the intention is to limit the port to only be used by a specific number of hosts at once. https://www.ciscopress.com/articles/article.asp?p=1722561 Adding: By default, Cisco IOS sets the aging time (aging time) of port security table entry to 0 (zero), which means that the entry will be removed immediately when a device disconnects. Therefore, by disconnecting the MAC device currently connected to the port, you can immediately connect another device without causing a violation.
upvoted 5 times
...
krzysiew
2 years, 1 month ago
I checked packet tracert 1.#switchport mode access 2.#switchport port-security 3.#switch port-security sticky 4.#switchport port-security maximum 2
upvoted 5 times
...
gc999
2 years, 1 month ago
I think "shutdown" is incorrect as it will cause the first two devices cannot use as well. It said we should "permit" them to use.
upvoted 1 times
...
SVN05
2 years, 2 months ago
Agreed with Peter_panda & HeinyHo. I've seen a few places mentioning that port security was usually configured on access ports(including pkt labs and other sites that explain how to implement port security concept for ccna) so my answer as follows. 1.switchport mode access 2.switchport port-security 3.switchport port-security maximum 2 4.switchport port-security violation shutdown Based on my experience with going over alot of questions here, Cisco takes everything literally so if the question says permit only two random MAC addresses at a time indicates it can be always changed to something else. Sticky will be a permanent mark on the MAC table thus not allowing any other device to associate with it.
upvoted 4 times
ike110
2 years, 2 months ago
"violation shutdown". is the default mode, so not needed unless another mode was set earlier
upvoted 3 times
Dutch012
2 years, 1 month ago
right, it is not needed but it completes what the question is asking for
upvoted 4 times
...
...
...
kalidergr
2 years, 4 months ago
Port security will only work on access ports. Therefore, in order to enable port security, the user must first make the port an access port. Source: https://cowbell.insure/blog/port-security-2/
upvoted 1 times
...
clivebarker86
2 years, 6 months ago
don t understand, why shutdown..?
upvoted 1 times
...
clivebarker86
2 years, 6 months ago
don t understand, why shutdown..?
upvoted 1 times
...
splashy
2 years, 7 months ago
switchport mode access command is essential Switch>enable Switch#conf t Enter configuration commands, one per line. End with CNTL/Z. Switch(config)#int f0/1 Switch(config-if)#switchport port-security Command rejected: FastEthernet0/1 is a dynamic port. Shutdown is default setting so no need to specify
upvoted 6 times
...
GohanF2
2 years, 9 months ago
The answers are correct. sticky is not an option . Due that it will saved the first 2 MAC addresses to the running configuration. IF any other device " randomly" connects to the same port then the connection will be refused till we cleared the sticky mac addresses
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago