exam questions

Exam 200-301 All Questions

View all questions & answers for the 200-301 exam

Exam 200-301 topic 1 question 610 discussion

Actual exam question from Cisco's 200-301
Question #: 610
Topic #: 1
[All 200-301 Questions]

Refer to the exhibit. Which statement about the interface that generated the output is true?

  • A. A syslog message is generated when a violation occurs.
  • B. One secure MAC address is manually configured on the interface.
  • C. One secure MAC address is dynamically learned on the interface.
  • D. Five secure MAC addresses are dynamically learned on the interface.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
C3L4H1R
Highly Voted 4 years, 1 month ago
A is incorrect, it does not send syslog message, read this: http://cisco.num.edu.mn/CCNA_R&S2/course/module2/2.2.4.4/2.2.4.4.html
upvoted 7 times
Sal34
2 years, 11 months ago
The answer is b. It increases the violation counter in the shutdown state and does not send a syslog message. Thanks, C3L4H1R.
upvoted 2 times
...
sgashashf
3 years, 1 month ago
This is horribly dated info. All modern sources will tell you that "shutdown" also generates a syslog message.
upvoted 19 times
RougePotatoe
2 years, 5 months ago
To back up his claim the following is from the cert guide: "If Example 6-7 had used the restrict violation mode instead of protect, the port status would have also remained in a secure-up state; however, IOS would show some indication of port security activity, such as an accurate incrementing violation counter, as well as syslog messages."
upvoted 2 times
...
...
...
[Removed]
Highly Voted 1 year, 7 months ago
bad question or bad study sources... A and B are correct I tihnk
upvoted 6 times
...
MeysamDavabi
Most Recent 2 months ago
Selected Answer: B
OOOOOOOOOOOOOMMMMMMMMMMGGGGGGGGGG first read the question then answer it says which statement that generate this output is TRUE? option A is the correct Concept but it DOES NOT GENERATE this output, So you are left just with option B which is TRUE and GENERATE this output. Although I checked the output on LAB when you hit the command : Switchport port-security violation shutdown or restrict in both cases SYSlog will be GENERATE just one difference in restrict mode it will not put interface in error disable mode. good luck
upvoted 1 times
...
matass_md
9 months, 1 week ago
Selected Answer: A
A and B are both correct , this question is wrong . For shutdown (default) port will go in err-disable and generate a syslog message . For Restrict , port will generate a syslog message and drop the packets . For Protect port will just drop the packet without a syslog message . and yes there is only 1 MAC address learned static .
upvoted 2 times
...
[Removed]
1 year, 1 month ago
Selected Answer: B
B is correct
upvoted 1 times
...
baanyan
1 year, 3 months ago
2 syslog will appear, one is port going into error disable mode, one is security violation occurred. So, A is incorrect
upvoted 2 times
...
[Removed]
1 year, 8 months ago
The documentation is confusing, some of them says shutdown mode sends logs and snmp traps (oficcial cert book from wendell odom book 2 chap 6 page 115) and other sites says the opposite like cisco catalyst configuration .... https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9500/software/release/16-10/configuration_guide/sec/b_1610_sec_9500_cg/b_1610_sec_9500_cg_chapter_0101010.html
upvoted 2 times
...
[Removed]
1 year, 9 months ago
Selected Answer: B
B. One secure MAC address is manually configured on the interface. Configured MAC addresses : 1
upvoted 2 times
...
gachocop3
3 years, 1 month ago
isn't A also correct because SNMP trap and Syslog message are generated in shutdown mode?
upvoted 5 times
...
babaKazoo
3 years, 3 months ago
B is correct. Why A is wrong for this question: It is true that when a Shutdown happens it is logged and incremented but in this example the max MAC address limit has not been reached. So the next violation of an unknown MAC address will simply be learned without causing a shutdown.
upvoted 4 times
sgashashf
3 years, 1 month ago
Your logic is flawed. The question doesn't ask what will happen when a new MAC is detected, it asks what will happen when a violation occurs, which implies a 6th MAC is detected. The question is just wrong.
upvoted 9 times
...
...
dave1992
3 years, 6 months ago
B is correct, restrict increments the violation counter, and shutdown sends a trap notification to the SNMP manager
upvoted 2 times
...
imo90s
3 years, 11 months ago
Answer B is correct. Restrict mode is the only one that generates syslog violation.
upvoted 2 times
Subit123
3 years, 11 months ago
Restrict: The offending frame is dropped and an SNMP trap and a Syslog message are generated. The security violation causes the violation counter to increment. Shutdown: The offending frame is dropped. The interface is placed in an error-disabled state and an SNMP trap and a Syslog message are generated.
upvoted 11 times
Sal34
2 years, 11 months ago
yea the answer is both a and b. it should show select 2 answers.
upvoted 2 times
Sal34
2 years, 11 months ago
After reading C3L4H1R's post. I think the answer is a.
upvoted 1 times
...
...
...
...
mrsiafu
3 years, 12 months ago
this question is all over the place...
upvoted 3 times
...
MM_9
4 years, 3 months ago
B is correct but also A?
upvoted 2 times
nakres64
4 years, 2 months ago
I think A is also correct, (if there is a valid SNMP configuration)
upvoted 2 times
FloridaMan88
4 years, 2 months ago
A is correct, but only AFTER all the allowed MAC addresses are learned. As of "now" in the print out only 1 of 5 MAC addresses are learned/ configured, so no violation yet.
upvoted 4 times
hema5tho
3 years, 7 months ago
That doesn't change the duality of the question. A) says when a violation occurs. And a violation would be 6 Mac addresses under that interface, doesn't matter how many MAC's are there now.
upvoted 4 times
...
pagamar
3 years, 4 months ago
Agree with hema5tho. A is also correct, as far as I know, despite the CCNA course says Shutdown violation mode does not generate a Syslog message (one error out of many?). But forther investigation is needed; may be this is different among various IOS versions.
upvoted 1 times
...
...
...
GHH
3 years, 5 months ago
They are both correct but something my cisco teacher told me is often on the exam there are multiple correct answers, but you have to choose the one "best" answer. This can mean the most specific correct answer or the most relevant correct answer, etc. In this case I think you chose the one most relevant. So my guess is that because most of the answers are referring to the MAC addresses learned on the interface, B is the better answer.
upvoted 4 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago