N10-009 exam dumps

N10-009 practice question 275 of 329

Network+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

N10-009 Question 275

Single answer

A company is tightening security in a conference room where employees, contractors, and visitors often connect devices to wall jacks. The network team wants to prevent unauthorized devices from gaining access, while still allowing domain-joined employee laptops to connect automatically using corporate credentials. The team also wants a control that is stronger than simple MAC-based allowlists, since users have previously bypassed MAC filtering by spoofing addresses. Which solution BEST meets these requirements?

  1. A

    Enable 802.1X on the switch ports and integrate it with a NAC solution backed by an authentication server

  2. B

    Configure static MAC filtering on each switch port and update the allowed MAC list whenever a new device is deployed

  3. C

    Disable all unused switch ports in the conference room and leave active ports open for any connected device

  4. D

    Enable port security with a maximum of one MAC address per port and use the default switch administrator password for emergency access

Show answer and explanation

Correct answer: A

Explanation

The best answer is to deploy 802.1X with NAC and a central authentication service. In enterprise environments, 802.1X is the standard control for authenticating endpoints before granting network access, and NAC extends this by enforcing policy based on user identity, device posture, or role. This directly addresses the requirement to allow managed employee laptops to connect automatically while blocking or restricting unauthorized devices. By contrast, MAC filtering and basic port security are weaker controls because MAC addresses can be spoofed and do not strongly verify identity. Disabling unused ports and changing default passwords are still important hardening steps, but they do not by themselves solve the access-control problem described. This aligns with common vendor and industry best practices for switch hardening and secure access control, including IEEE 802.1X for port-based authentication and standard guidance to disable unused interfaces and replace default credentials.

  • A. Correct.

    Correct. 802.1X provides port-based network access control by requiring authentication before a device is granted network access. When integrated with NAC and a backend authentication server such as RADIUS, it can validate user or device credentials and apply policy-based access. This is stronger than MAC filtering because MAC addresses can be spoofed, whereas 802.1X commonly uses certificates or directory-based credentials for authentication. This also supports the requirement for domain-joined employee laptops to connect automatically using corporate credentials.

  • B. Incorrect.

    Incorrect. MAC filtering is relatively weak because MAC addresses are easy to spoof with common tools. Although it can restrict access at a basic level, it does not meet the requirement for stronger authentication and becomes difficult to manage in environments with changing devices, contractors, and guests. This option reflects a common misconception that MAC allowlists provide robust identity validation.

  • C. Incorrect.

    Incorrect. Disabling unused ports is a good device-hardening practice and should be part of a secure switch configuration, but it does not control who can use ports that remain active. In this scenario, the risk is unauthorized devices connecting to live conference room jacks, so leaving active ports unrestricted would not satisfy the requirement.

  • D. Incorrect.

    Incorrect. Port security can limit the number of MAC addresses learned on a port and can help reduce casual misuse, but it still relies on MAC addresses and does not provide user or device authentication comparable to 802.1X. In addition, leaving the default administrator password in place is poor security practice and directly violates device-hardening best practices. Changing default passwords is a foundational requirement for secure infrastructure.

Timed practice exam

Take a N10-009 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam