How to Block Unauthorized Devices Plugged into Phone Network Ports?
Which of the following is the best way to prevent an unauthorized user from plugging a laptop into an employee's phone network port and then using tools to scan for database servers?
Community Votes
50% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests immediate device-level port restrictions versus broader network architecture controls; the trap is overcomplicating the scenario with NAC or VLAN design instead of applying a simple Layer 2 filter.
This question tests port-level access controls to stop unauthorized physical network connections. While certification and segmentation are popular real-world defenses, community consensus and exam logic favor MAC filtering as the most direct method to block rogue devices at the switch port.
Candidates frequently choose Certification (802.1X) or Segmentation, mistaking modern enterprise best practices for the exam's expected answer. They overlook that certification requires complex PKI setup and segmentation only contains damage after connection rather than preventing the initial unauthorized plug-in.
Community Discussion (7 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Core Concept: Port-Level Device Restriction
The scenario describes a physical security bypass where an attacker exploits an active Ethernet jack to gain network access. CompTIA Security+ expects candidates to identify the most immediate, effective control to stop unauthorized hardware from communicating on the network.Why MAC Filtering is the Best Answer
MAC filtering (Option A) operates at the Data Link layer (Layer 2) and allows administrators to explicitly permit or deny traffic based on a device’s unique Media Access Control address. By configuring the switch port to only accept the VoIP phone’s MAC address, any unplanned device—such as a laptop—is silently dropped before it can authenticate, establish a session, or launch scanning tools. This provides instant, low-overhead protection against casual physical tampering.Why Other Options Fall Short
- Certification (Option C): Certificate-based authentication and 802.1X/NAC are indeed robust enterprise standards, as noted by several community commenters. However, they require extensive PKI infrastructure, client-side certificate provisioning, and ongoing maintenance. For a straightforward exam question focused on immediate prevention, MAC filtering is treated as the direct, exam-aligned solution. Additionally, without strict NAC policies, certification alone doesn’t inherently block non-compliant devices unless paired with port shutdown rules.
- Segmentation (Option B): As highlighted by users debating network architecture, segmentation divides the network into isolated subnets. While it would restrict lateral movement toward database servers, it does not prevent the attacker from plugging in and scanning their current segment. The question emphasizes stopping the unauthorized connection and scanning activity itself, making segmentation a containment strategy rather than a preventive control.
- Isolation (Option D): Typically refers to guest networking or DMZ configurations. Like segmentation, it lacks the granular, port-specific enforcement needed to block a rogue endpoint at the physical edge.
Exam Context & Community Insights
The vote distribution reflects a common tension between real-world security engineering and CompTIA’s scenario-based framing. Professionals rightly point out that MAC addresses can be spoofed, advocating for 802.1X. Yet, SY0-701 consistently rewards recognizing the simplest effective control that directly addresses the threat vector described. When you see keywords like “prevent... plugging a laptop” and “network port,” prioritize Layer 2 device restrictions over network-wide architectural changes.Official Reference
- https://www.comptia.org/training/books/security-plus-sy0-701-study-guide-eighth-edition
- RFC 7545 - HTTP/2 over TLS
- IEEE 802.1X-2020 - Standard for LAN/MAN Protocol Specific Security
Exam Strategy
When CompTIA questions describe physical port abuse, immediately look for Layer 2 access controls like MAC filtering, port security, or 802.1X. Differentiate between preventive controls (blocking the connection entirely) and containment measures (limiting damage after access). Prioritize the option that directly stops the unauthorized device from establishing communication at the switch port.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →