Question 1
IntermediateSecurity and QoS · Port Security Configuration
A financial services company is implementing a new access layer using Aruba CX 6200F switches. To comply with security policies, any port that connects to an end-user device must only allow a single, specific MAC address to communicate. If an unauthorized device is connected, the port should immediately be disabled and an SNMP trap sent to the monitoring system. Which set of commands correctly implements this policy on interface 1/1/1?
Answer and explanation
Correct answer: B
This configuration correctly meets all requirements. port-security enable activates the feature. mac-address sticky learns the first MAC address and binds it to the port. client-limit 1 enforces the single device policy. violation-mode shutdown-notify is the correct syntax in AOS-CX to both disable the port (shutdown) and send an SNMP trap (notify) upon violation.
