Security Fundamentals
Targeted CCNA practice for this exam objective, with an explanation for every answer option.
- Certification
- CCNA
- Domain
- Security Fundamentals
- Questions
- 10
Practice CCNA Security Fundamentals questions with exam-style scenarios, detailed explanations, and option-by-option rationale for this domain.
Example question from this objective
Each option is explained, so the reasoning behind the distractors is part of the answer.
A security policy allows only registered endpoint hardware to connect to a specific switchport. Which control uses the source hardware address as part of the decision?
- Syslog severity filtering
- NTP polling
- BGP route advertisement
- MAC address filtering
Syslog severity filtering — Syslog severity filtering controls logging output and does not restrict switchport hardware addresses.
NTP polling — NTP polling checks time sources and does not filter endpoints by MAC address.
BGP route advertisement — BGP route advertisement exchanges network prefixes and is unrelated to access-port endpoint filtering.
MAC address filtering — MAC address filtering permits or blocks traffic based on device MAC addresses.