Which of the following countermeasure can specifically protect against both the MAC Flood and MAC Spoofing attacks?
A.
Port Security
B.
Switch Mapping
C.
Port Reconfiguring
D.
Multiple Recognition
Explanation:
With Port Security the switch will keep track of which ports are allowed to send traffic on a port.
Most of the time Port Security limits the number of MAC addresses per port
But limiting the number of MAC addresses to a port doesn’t prevent hacktop from plugging into the network with a sniffing-only cable (Transmit wires cut) and picking a mac address to use and spoofing it. MAC-based port security has been deprecated in favor of 802.11x certificate security.
???
mac addr security can do static or dynamic and have limits imposed upon how many addresses can be used on that port, before the port is shutdown
this question says noting about sniffing, but implies a man in the middle or arp hijack attempt