How to Prevent Unauthorized Physical Network Access via Lobby Jacks?
A visitor plugs a laptop into a network jack in the lobby and is able to connect to the company's network. Which of the following should be configured on the existing network infrastructure to best prevent this activity?
Community Votes
83% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
It tests the distinction between physical/port-level access controls and higher-layer encryption/authentication, with the common trap being confusion with NAC protocols like 802.1X that require additional configuration beyond basic switch settings.
This question focuses on securing physical network ports to block unauthorized device connections. The community overwhelmingly agrees that configuring port security on switches is the most effective baseline control to restrict access by MAC address or port state.
Candidates often select Transport Layer Security (C), mistakenly equating it with network access control or confusing it with EAP-TLS used in 802.1X authentication, when TLS itself is merely an encryption protocol, not a port-access control mechanism.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Core Concept
The scenario describes unauthorized physical network access via an unsecured Ethernet jack. To mitigate this, network administrators must implement controls at the data link layer (Layer 2) to regulate which devices can communicate through a specific switch port.Why Port Security is Correct
Port security is a native switch feature designed specifically to limit and identify MAC addresses allowed on a given interface. By enabling it, administrators can restrict connections to pre-approved devices, dynamically learn "sticky" MAC addresses, or shut down the port upon detecting an unauthorized device. As noted by multiple candidates, this provides immediate, infrastructure-level enforcement without requiring client-side software or complex authentication servers.Why Other Options Are Incorrect
Web application firewalls (WAF) operate at Layer 7 to filter HTTP/HTTPS traffic targeting web applications, offering zero protection against raw Layer 2/Layer 3 network access. Transport layer security (TLS) encrypts data in transit but does not authenticate or authorize device attachment to a physical port; while TLS underpins EAP-TLS for 802.1X, selecting TLS alone misidentifies the actual access-control mechanism. Virtual private networks (VPNs) create encrypted tunnels over existing networks but assume the device is already connected to the underlying infrastructure, making them ineffective at preventing initial unauthorized plug-in access.Community Insights
The voting distribution heavily favors Option A (83%), confirming its status as the expected CompTIA answer. One candidate pointed out that while 802.1X/NAC solutions (which may use TLS/EAP-TLS) offer stronger authentication, they require additional infrastructure like RADIUS servers and client supplicants. In contrast, port security works directly on existing switch hardware, aligning perfectly with the question’s constraint to configure the "existing network infrastructure."Official Reference
- Cisco IOS Switch Port Security Configuration Guide
- https://www.cisco.com/c/en/us/support/docs/switches/catalyst-2960-series-switches/2960-psp-guide.html
- CompTIA Security+ SY0-701 Exam Objectives
- RFC 3748: Extensible Authentication Protocol (EAP)
Exam Strategy
When questions mention plugging a device into a physical wall jack or switch port, immediately prioritize Layer 2 controls like port security, 802.1X, or DHCP snooping before considering transport-layer encryption or application-layer defenses. Always match the solution to the exact infrastructure mentioned; if the prompt specifies "existing network infrastructure," choose features natively supported by standard switches rather than requiring new server deployments or client software.
Related Analysis
Practice All SY0-701 Questions
Access 100 questions with complete answers and detailed explanations.
View Full SY0-701 Practice Test →