f. None of the above

12. What is not a feature of port security for switches?

a. Block input to Ethernet, Fast Ethernet, and Gigabit ports.

b. Functions by analyzing MAC address and comparing it to authorized MACs.

c. The global resource on a system is 2048 MAC addresses plus a default MAC address.

d. The port can dynamically configure itself by the attached device's MAC address.

e. MACs are stored in NVRAM.

13. Which of the following statements is true when configuring port security?

a. Port security cannot be configured on a trunk port.

b. Port security cannot be enabled on a SPAN port.

c. Dynamic, static, or permanent CAM entries cannot be configured on a secured port.

d. When port security is enabled, any static or dynamic CAM entries associated with the port are cleared.

e. All of the above.

14. What does the AutoSecure feature do within Cisco IOS?

a. Reads configuration and makes recommendations to secure platform b. Enables IP security services and disables common vulnerabilities c. Secures communications with other systems d. Enables detailed audit logging and tracking e. Turns on heuristic analysis to auto-block new threats

The answers to the "Do I Know This Already?" quiz are found in the appendix. The suggested choices for your next step are as follows:

• 12 or less overall score Read the entire chapter. This includes the "Foundation Topics" and "Foundation Summary" sections and the "Q&A" section.

• 13 or 14 overall score If you want more review on these topics, skip to the "Foundation Summary" section and then go to the "Q&A" section. Otherwise, move on to Chapter 6, "Authentication."



