To secure unused switch ports that are in the default VLAN, which two actions should you take? (Choose two.)
Choose an answer
Tap an option to check your answer.
Correct answer: Configure the port type as access and place in VLAN 99., Administratively shut down the ports..
Why this is the answer
To secure unused switch ports, you should administratively shut them down. This prevents unauthorized physical access to the network through these ports. Additionally, configuring the port type as access and placing them in an unused VLAN (like VLAN 99, often designated as a "black hole" VLAN) isolates them from active network traffic. This prevents any accidental or malicious connection from gaining access to production VLANs even if the port is somehow reactivated. Configuring ports as trunk ports would allow multiple VLANs, increasing the attack surface. Enabling Cisco Discovery Protocol (CDP) is a management protocol and doesn't secure ports. Configuring EtherChannel bundles multiple ports for increased bandwidth or redundancy, not security for unused ports.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed