Which port-security violation mode drops frames from unauthorized MACs while allowing frames from authorized MACs?
Choose an answer
Tap an option to check your answer.
Correct answer: protect.
Why this is the answer
The protect violation mode drops frames from unauthorized MAC addresses without generating any log messages or SNMP traps. It simply discards frames from unknown sources while allowing traffic from learned, authorized MAC addresses to continue. This mode is useful when you want to prevent unauthorized devices from communicating but don't need immediate notification of violations. restrict also drops unauthorized frames but generates a syslog message and increments a violation counter, providing more visibility. shutdown disables the port immediately upon detecting a violation, requiring manual intervention or error recovery to re-enable it. shutdown VLAN is not a standard port-security violation mode.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed