How to Block Unauthorized Devices Plugged into Phone Network Ports?

Which of the following is the best way to prevent an unauthorized user from plugging a laptop into an employee's phone network port and then using tools to scan for database servers?

  1. MAC filtering Source Reference Answer
  2. Segmentation
  3. Certification
  4. Isolation

Community Votes

A
50%
C
31%
B
19%

50% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests immediate device-level port restrictions versus broader network architecture controls; the trap is overcomplicating the scenario with NAC or VLAN design instead of applying a simple Layer 2 filter.

This question tests port-level access controls to stop unauthorized physical network connections. While certification and segmentation are popular real-world defenses, community consensus and exam logic favor MAC filtering as the most direct method to block rogue devices at the switch port.

Candidates frequently choose Certification (802.1X) or Segmentation, mistaking modern enterprise best practices for the exam's expected answer. They overlook that certification requires complex PKI setup and segmentation only contains damage after connection rather than preventing the initial unauthorized plug-in.

Community Discussion (7 comments)

1f2b013 👍 7 Selected: A
MAC filtering is a network access control mechanism that allows or blocks devices based on their Media Access Control (MAC) addresses. By implementing MAC filtering, the network can restrict access to authorized devices only, preventing an unauthorized laptop from connecting and conducting scans, even if it is physically plugged into a network port.
CSue 👍 1 Selected: C
Certification (i.e., 802.1X or certificate-based authentication) is indeed the most effective way to ensure that unauthorized devices, like a laptop plugged into an employee’s phone port, cannot access the network without proper authentication. 802.1X is a network access control protocol that requires devices to authenticate before gaining network access, preventing unauthorized access even if the device is physically plugged into the port MAC filtering: While this can limit access to devices with specific MAC addresses, it's less secure because MAC addresses can be easily spoofed. However, it's a supplementary measure that could be useful in tandem with other controls like 802.1X.
9149f41 👍 1 Selected: A
MAC filtering can be done by mobile (based on the mobile device, e.g., an Android phone is usually available) setting or MDM with the company application.
rob79 👍 2 Selected: C
This should be certification, as the attacker can spoof the phones MAC address, by deploying certification with 802.1x there is greater security than MAC filtering.
Eracle 👍 2 Selected: B
Network segmentation divides the physical network into logical subnets isolated from each other. If an unauthorized user connects to the network port of an employee's phone, he will be within the employee network segment. Because of the segmentation, he will not have direct access to the network segment where the database servers reside. Even if he were to perform a network scan, he would see only the devices in his own segment, not the database servers.
jbmac 👍 1 Selected: B
The correct answer is: B. Segmentation Explanation: Segmentation involves dividing a network into smaller, isolated sub-networks or segments. By segmenting the network, you can control which devices or users have access to specific parts of the network. In this case, segmentation would prevent an unauthorized user from accessing sensitive parts of the network (such as the database servers) even if they plug their laptop into a network port. The unauthorized laptop would be placed on a segment of the network that does not have access to critical resources, thereby preventing scans and unauthorized access.
Becccca 👍 2 Selected: C
Certification (i.e., using 802.1X or certificate-based authentication) is the most effective way to ensure that simply plugging a laptop into a phone port will not grant unauthorized network access. The switch will refuse to pass traffic until the device proves it has valid authentication—effectively stopping casual plug-ins and scans in their tracks.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Core Concept: Port-Level Device Restriction

The scenario describes a physical security bypass where an attacker exploits an active Ethernet jack to gain network access. CompTIA Security+ expects candidates to identify the most immediate, effective control to stop unauthorized hardware from communicating on the network.

Why MAC Filtering is the Best Answer

MAC filtering (Option A) operates at the Data Link layer (Layer 2) and allows administrators to explicitly permit or deny traffic based on a device’s unique Media Access Control address. By configuring the switch port to only accept the VoIP phone’s MAC address, any unplanned device—such as a laptop—is silently dropped before it can authenticate, establish a session, or launch scanning tools. This provides instant, low-overhead protection against casual physical tampering.

Why Other Options Fall Short

  • Certification (Option C): Certificate-based authentication and 802.1X/NAC are indeed robust enterprise standards, as noted by several community commenters. However, they require extensive PKI infrastructure, client-side certificate provisioning, and ongoing maintenance. For a straightforward exam question focused on immediate prevention, MAC filtering is treated as the direct, exam-aligned solution. Additionally, without strict NAC policies, certification alone doesn’t inherently block non-compliant devices unless paired with port shutdown rules.
  • Segmentation (Option B): As highlighted by users debating network architecture, segmentation divides the network into isolated subnets. While it would restrict lateral movement toward database servers, it does not prevent the attacker from plugging in and scanning their current segment. The question emphasizes stopping the unauthorized connection and scanning activity itself, making segmentation a containment strategy rather than a preventive control.
  • Isolation (Option D): Typically refers to guest networking or DMZ configurations. Like segmentation, it lacks the granular, port-specific enforcement needed to block a rogue endpoint at the physical edge.

Exam Context & Community Insights

The vote distribution reflects a common tension between real-world security engineering and CompTIA’s scenario-based framing. Professionals rightly point out that MAC addresses can be spoofed, advocating for 802.1X. Yet, SY0-701 consistently rewards recognizing the simplest effective control that directly addresses the threat vector described. When you see keywords like “prevent... plugging a laptop” and “network port,” prioritize Layer 2 device restrictions over network-wide architectural changes.

Official Reference

Exam Strategy

When CompTIA questions describe physical port abuse, immediately look for Layer 2 access controls like MAC filtering, port security, or 802.1X. Differentiate between preventive controls (blocking the connection entirely) and containment measures (limiting damage after access). Prioritize the option that directly stops the unauthorized device from establishing communication at the switch port.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide