I don't think it's a good question , because “protect” and “restrict” also allows traffic from passing with a valid
https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst6500/ios/12-2SX/configuration/guide/book/port_sec.pdf
When configuring port security violation modes, note the following information:
• protect—Drops packets with unknown source addresses until you remove a sufficient number of
secure MAC addresses to drop below the maximum value.
• restrict—Drops packets with unknown source addresses until you remove a sufficient number of
secure MAC addresses to drop below the maximum value and causes the SecurityViolation counter
to increment.
• shutdown—Puts the interface into the error-disabled state immediately and sends an SNMP trap
notification.
restrict also sends a SNMP trap. Tylosh is right both "“protect” and “restrict” also allows traffic from passing with a valid MAC... but as Bieley says: "Always apply the answer with the least privileges. So protect."
i believe when he mention blocked invalid mac address meant not increment the counter
other than that either protect or restrict are blocking the invalid MAC address .
C is correct
- protect: when the maximum number of secure MAC addresses has been reached, packets from devices with unknown source addresses are dropped until you remove the necessary number of secure MAC addresses from the table. In this mode, you are not notified when a security violation occurs.
- restrict: is identical with protect mode, but notifies you when a security violation occurs. Specifically, a SNMP trap is sent, a syslog message is logged and the violation counter increments.
Protect – When a violation occurs in this mode, the switchport will permit traffic from known MAC addresses to continue sending traffic while dropping traffic from unknown MAC addresses. When using this mode, no notification message is sent when this violation occurs.
https://www.pluralsight.com/blog/it-ops/switchport-security-concepts#:~:text=Protect%20%E2%80%93%20When%20a%20violation%20occurs,sent%20when%20this%20violation%20occurs.
upvoted 1 times
...
This section is not available anymore. Please use the main Exam Page.200-301 Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Tylosh
Highly Voted 2Â years, 1Â month agolucasleeli
6Â months, 1Â week agocreaguy
2Â years, 1Â month agorogi2023
1Â year, 7Â months agoBieLey
2Â years agoMinSun600
Most Recent 1Â week, 4Â days ago[Removed]
7Â months agoNewJeans
1Â year ago[Removed]
1Â year, 1Â month agoVicM
1Â year, 5Â months ago