How to Prevent Unauthorized Physical Network Access via Lobby Jacks?

A visitor plugs a laptop into a network jack in the lobby and is able to connect to the company's network. Which of the following should be configured on the existing network infrastructure to best prevent this activity?

  1. Port security Source Reference Answer
  2. Web application firewall
  3. Transport layer security
  4. Virtual private network

Community Votes

A
83%
C
17%

83% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

It tests the distinction between physical/port-level access controls and higher-layer encryption/authentication, with the common trap being confusion with NAC protocols like 802.1X that require additional configuration beyond basic switch settings.

This question focuses on securing physical network ports to block unauthorized device connections. The community overwhelmingly agrees that configuring port security on switches is the most effective baseline control to restrict access by MAC address or port state.

Candidates often select Transport Layer Security (C), mistakenly equating it with network access control or confusing it with EAP-TLS used in 802.1X authentication, when TLS itself is merely an encryption protocol, not a port-access control mechanism.

Community Discussion (5 comments)

dbrowndiver 👍 6 Selected: A
Port security is a feature available on network switches that helps secure access to the physical network by restricting which devices can connect to each network port based on their MAC address. Port Security: This is a network security feature that restricts input to an interface by limiting and identifying MAC addresses of the devices allowed to access the port. It can be configured to block devices that do not match the allowed list. -Control Over Physical Access: By enabling port security on the network jacks, the organization can ensure that only authorized devices with specific MAC addresses are allowed to connect. Any unauthorized devices, such as a visitor's laptop, would be blocked from accessing the network. -Dynamic or Static Configuration: Port security can dynamically learn and store allowed MAC addresses or use a predefined list, providing flexibility in securing physical network ports. This why it is the best answer: Port security directly addresses the issue of unauthorized access through physical network connections by controlling which devices can use the network ports. It prevents unauthorized devices from gaining network access, making it the most appropriate solution for this scenario.
41c27e6 👍 1 Selected: A
Port security is a feature that can be configured on network switches to limit which devices can connect to specific ports
Andrewyounan 👍 3 Selected: C
I go more for TLS which is part of EAP-TLS used with 802.1X on the NAC to authenticate. On the other hand, Port Sec. you'll need to either identify the MAC address or Sticky MAC address, so it makes sense to go with C. ### Maybe I'm over-thinking ### :D
Shaman73 👍 4 Selected: A
A. Port security
MAKOhunter33333333 👍 4 Selected: A
Port security / 802.1x / NAC

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Core Concept

The scenario describes unauthorized physical network access via an unsecured Ethernet jack. To mitigate this, network administrators must implement controls at the data link layer (Layer 2) to regulate which devices can communicate through a specific switch port.

Why Port Security is Correct

Port security is a native switch feature designed specifically to limit and identify MAC addresses allowed on a given interface. By enabling it, administrators can restrict connections to pre-approved devices, dynamically learn "sticky" MAC addresses, or shut down the port upon detecting an unauthorized device. As noted by multiple candidates, this provides immediate, infrastructure-level enforcement without requiring client-side software or complex authentication servers.

Why Other Options Are Incorrect

Web application firewalls (WAF) operate at Layer 7 to filter HTTP/HTTPS traffic targeting web applications, offering zero protection against raw Layer 2/Layer 3 network access. Transport layer security (TLS) encrypts data in transit but does not authenticate or authorize device attachment to a physical port; while TLS underpins EAP-TLS for 802.1X, selecting TLS alone misidentifies the actual access-control mechanism. Virtual private networks (VPNs) create encrypted tunnels over existing networks but assume the device is already connected to the underlying infrastructure, making them ineffective at preventing initial unauthorized plug-in access.

Community Insights

The voting distribution heavily favors Option A (83%), confirming its status as the expected CompTIA answer. One candidate pointed out that while 802.1X/NAC solutions (which may use TLS/EAP-TLS) offer stronger authentication, they require additional infrastructure like RADIUS servers and client supplicants. In contrast, port security works directly on existing switch hardware, aligning perfectly with the question’s constraint to configure the "existing network infrastructure."

Official Reference

Exam Strategy

When questions mention plugging a device into a physical wall jack or switch port, immediately prioritize Layer 2 controls like port security, 802.1X, or DHCP snooping before considering transport-layer encryption or application-layer defenses. Always match the solution to the exact infrastructure mentioned; if the prompt specifies "existing network infrastructure," choose features natively supported by standard switches rather than requiring new server deployments or client software.

Related Analysis

Practice All SY0-701 Questions

Access 100 questions with complete answers and detailed explanations.

View Full SY0-701 Practice Test →

← Back to SY0-701 Study Guide