Network Security 14% Lesson 7 of 8

Lesson 4.3.1 — Device Hardening & Network Access Control

Avatar Of Asad IjazAsad Ijaz ·Sep 20, 2026 ·5 min read
88% through domain
Illustration Of A Fortress Wall With Unnecessary Side Doors Being Bricked Up, Leaving One Guarded Main Gate

Domain 4.0 | Network Security — 14% of exam

Learning Objectives

By the end of this lesson, you will be able to:

  • Explain device hardening practices, including disabling unused ports/services and changing default passwords
  • Describe port security as a Layer 2 defense against MAC-based attacks
  • Explain 802.1X as a network access control framework
  • Describe MAC filtering and its real-world limitations
  • Explain key management and why it matters for cryptographic security

Key Terms

TermDefinition
Device HardeningReducing a device’s attack surface by disabling unnecessary services, closing unused ports, and changing default credentials
Port SecurityA switch feature limiting which or how many MAC addresses are allowed on a given port
802.1XA network access control framework requiring authentication before a device is granted network access
MAC FilteringRestricting network access based on an allow or deny list of MAC addresses
Key ManagementThe secure generation, distribution, storage, rotation, and revocation of cryptographic keys

Explanation

From Attack Types to Defense

Objective 4.2 covered specific attack techniques in detail — MAC flooding, ARP poisoning, on-path attacks, and rogue devices and evil twins. This lesson covers concrete defenses, several of which map directly onto attacks already covered — port security exists specifically to prevent MAC flooding, and 802.1X exists specifically to prevent unauthorized rogue devices from simply plugging in and gaining network access.

Device Hardening: Reducing the Attack Surface

Device hardening is the general practice of reducing a device’s attack surface — the total set of ways it could potentially be compromised — by eliminating anything unnecessary:

Disabling unused ports and services removes potential entry points entirely. Every open port or running service represents a possible vulnerability waiting to be discovered; a service that isn’t running at all can’t be exploited, regardless of whether a vulnerability in it is ever found.

Changing default passwords addresses one of the most common and easily avoidable security failures. Default credentials for common device models are widely known and often published online — leaving a default password unchanged is essentially the same as having no password-based access control at all, since anyone who knows (or looks up) the default can walk right in.

Neither practice is glamorous or technically sophisticated, but both dramatically reduce the number of easy, low-effort attack paths available against a device.

Port Security: A Layer 2 Defense Against MAC Flooding

Port security is a switch feature that directly addresses the MAC flooding attack covered in the previous objective: by limiting the number of MAC addresses allowed on a given port — or restricting a port to one or a few specifically known, permitted addresses — port security prevents an attacker from ever successfully overwhelming the switch’s MAC table in the first place. When a port security violation occurs (too many MAC addresses observed, or an unrecognized MAC on a restricted port), the switch can be configured to take action — shutting the port down, restricting further learning, or simply logging the event.

Diagram Showing A Switch Port Allowing Only Two Mac Addresses And Shutting Down When A Third, Unauthorized Device Attempts To Connect
How Port Security Restricts The Number Or Identity Of Mac Addresses Allowed On A Switch Port

802.1X: Network Access Control at the Port Level

802.1X takes network access control further, requiring a device to successfully authenticate before it’s granted any meaningful network access at all — not just limiting which MAC addresses are allowed, but actually verifying identity before opening the port up for regular traffic. 802.1X typically works alongside a backend authentication server — commonly RADIUS, covered earlier in this module — which the switch or access point consults to actually verify the connecting device or user’s credentials.
Diagram Showing A Device Authenticating Against A Radius Server Before A Switch Port Opens To Allow Network Traffic
How 802.1X Requires Successful Authentication Against A Backend Server Before Granting Network Access

This is exactly the mechanism that prevents the kind of casual rogue device scenario covered earlier — an unauthorized device (or a well-meaning employee’s personal access point) simply plugging into an open switch port and immediately gaining network access. With 802.1X properly enforced, an unauthenticated device connecting to that port gets essentially nothing until it successfully proves its identity.

MAC Filtering and Its Limitations

MAC filtering restricts network access based on a list of allowed or denied MAC addresses — conceptually simple, and available on nearly every consumer and enterprise wireless access point. The significant limitation is that MAC addresses can be trivially spoofed: an attacker who observes a permitted MAC address on the network (which isn’t difficult, since MAC addresses are visible in plain traffic) can simply configure their own device to present that same address, defeating the filter entirely. MAC filtering is still commonly used as one layer of defense, but it should never be relied upon as a strong, standalone access control — 802.1X’s actual authentication provides meaningfully stronger protection.

Key Management

Key management covers the full lifecycle of cryptographic keys: secure generation, controlled distribution to only the parties who legitimately need them, protected storage (recall from the PKI lesson that a private key must never leave its owner’s control), periodic rotation to limit the damage if a key is ever compromised, and prompt revocation when a key genuinely is compromised or an associated certificate needs to be invalidated.
Circular Diagram Showing The Key Management Lifecycle Stages: Generation, Distribution, Storage, Rotation, And Revocation
The Full Lifecycle A Cryptographic Key Moves Through, From Generation To Eventual Revocation

Poor key management can undermine even a technically sound cryptographic system entirely — strong encryption built on a poorly protected or carelessly distributed key provides little real security, since the strength of the underlying algorithm matters far less than how well the actual key is protected in practice.

Recognition-Level Verification Concepts

A few patterns are worth recognizing on sight:

  • A switch port configured to allow only one or two specific MAC addresses, shutting down if violated, is port security in action.
  • A device unable to pass any meaningful traffic until it successfully authenticates against a RADIUS server describes 802.1X enforcement.
  • An access point relying solely on an allow-list of MAC addresses, with no further authentication, is using MAC filtering — a weaker control than it might initially appear.
  • A described process covering how a cryptographic key is created, distributed, stored, and eventually retired describes key management as a whole lifecycle, not a single one-time action.

Common Exam Traps

  • Port security and 802.1X are not the same mechanism, even though both operate at the switch port level. Port security is about MAC address quantity/identity; 802.1X is about actual authentication before granting access at all.
  • MAC filtering is a genuinely weak control on its own, since MAC addresses are trivially spoofable. Don’t treat it as equivalent in strength to real authentication mechanisms like 802.1X.
  • Disabling unused ports and services is a preventive measure, not a reactive one. It reduces the attack surface before an attack is even attempted, rather than responding to one already underway.
  • An unchanged default password isn’t a weak security control — it’s effectively no security control at all, given how widely known default credentials typically are.
  • Key management is a full lifecycle, not a single event. Generation alone, without proper distribution, storage, rotation, and revocation practices, leaves real gaps even for otherwise strong cryptography.

Lesson 4.3.1 Practice Quiz — Device Hardening & Network Access Control

17 questions covering device hardening, port security, 802.1X, MAC filtering, and key management.

N10-009 · Domain 4.3
Question 1Plain
What does port security limit?
Port security limits the number or identity of MAC addresses allowed on a given switch port, directly preventing MAC flooding.
Question 2Plain
What does 802.1X require before granting network access?
802.1X requires a device to successfully authenticate, typically against a backend RADIUS server, before granting meaningful network access.
Question 3Plain
What is a major weakness of MAC filtering?
MAC addresses are visible in plain traffic and can be trivially spoofed, making MAC filtering a weak standalone control.
Question 4Choose Two
Which two statements about device hardening are correct? (Choose two.)
Disabling unused services and changing default passwords both reduce attack surface — enabling more services increases exposure, and default passwords are widely known regardless of brand reputation.
Question 5Choose Two
Which two statements correctly distinguish port security from 802.1X? (Choose two.)
Port security governs MAC address quantity/identity, while 802.1X requires genuine authentication — these are distinct mechanisms, and MAC filtering is notably weaker than 802.1X, not stronger.
Question 6Choose Two
Which two statements about key management are correct? (Choose two.)
Key management is a full lifecycle — generation through revocation — and weak practices anywhere in that lifecycle can undermine an otherwise strong cryptographic system.
Question 7Scenario
A switch port keeps seeing an unusually high number of new, unexpected MAC addresses in a short period. What control should have been in place to prevent this?
This describes a MAC flooding attempt, which port security is specifically designed to prevent by limiting allowed MAC addresses.
Question 8Scenario
An unauthorized laptop is plugged into an open switch port and immediately gains full network access with no authentication required. What control's absence does this suggest?
Immediate, unauthenticated network access on plugging in is exactly what 802.1X enforcement is meant to prevent — its absence here is the gap.
Question 9Scenario
An attacker observes a permitted MAC address on the network and configures their own device to present that same address, bypassing an access point's access restriction. What weakness does this exploit?
Spoofing an allowed MAC address to bypass a filter is exactly the well-known weakness of MAC filtering as a standalone control.
Question 10Scenario
A newly deployed device is found still using its vendor-assigned default administrator password. What security practice was skipped?
Leaving a default password unchanged is exactly the kind of gap basic device hardening is meant to close.
Question 11Scenario
An organization discovers a private key has been compromised and needs to invalidate it immediately, before its scheduled expiration. What key management activity addresses this?
Revocation is exactly the key management activity for immediately invalidating a compromised key before its normal expiration.
Question 12Exhibit
Based on this switch configuration, what is being enforced?
SW1(config-if)# switchport port-security SW1(config-if)# switchport port-security maximum 2 SW1(config-if)# switchport port-security violation shutdown
The "switchport port-security" commands with a maximum MAC count and shutdown violation action are exactly a port security configuration.
Question 13Exhibit
Based on this authentication log, what mechanism is in use?
Access Log: Device connects to switch port Gi0/5 802.1X authentication initiated RADIUS server response: ACCESS-ACCEPT Port state: Now forwarding traffic
802.1X authentication explicitly initiated, with a RADIUS ACCESS-ACCEPT response before the port starts forwarding traffic, is exactly this mechanism in action.
Question 14Exhibit
Based on this incident report, what weakness was exploited?
Incident Report: Access Point Config: MAC filtering enabled, allow-list of 20 known devices Finding: Attacker device MAC address matched an allowed entry exactly Investigation: Attacker had cloned the MAC address of a legitimate allowed device
Cloning an allowed MAC address to bypass the filter is exactly the well-known spoofing weakness of MAC filtering.
Question 15Exhibit
Based on this audit finding, what gap was identified?
Device Audit Finding: Device: SW-EDGE-12 Admin Password: "admin123" (vendor default, unchanged since installation)
An unchanged vendor default password is exactly the device hardening gap this lesson describes.
Question 16Exhibit
Based on this audit finding, what hardening gap exists?
Device Audit Finding: Device: RTR-BRANCH-03 Open Services: Telnet (port 23) — ENABLED, unused, no known business need SSH (port 22) — ENABLED, actively used
Telnet running with no business need, alongside the actively used SSH, is exactly the kind of unnecessary service device hardening calls for disabling.
Question 17Exhibit
Based on this log, what key management activities are shown?
Key Management Log: 2026-01-15 — Key generated for TLS endpoint 2026-01-15 — Key securely distributed to authorized server only 2026-07-15 — Scheduled key rotation performed 2026-09-10 — Key revoked following suspected compromise
This log traces the full key management lifecycle from generation through distribution, rotation, and final revocation.
📝

Summary

Device hardening reduces attack surface by disabling unused ports and services and changing default credentials — simple practices that eliminate easy, low-effort attack paths.

Port security limits the number or identity of MAC addresses allowed on a switch port, directly preventing MAC flooding attacks.

802.1X requires actual authentication, typically against a backend RADIUS server, before granting meaningful network access, directly preventing casual rogue device connections.

MAC filtering restricts access by MAC address but is easily defeated through spoofing, making it a weak standalone control compared to genuine authentication.

Key management covers the full lifecycle of cryptographic keys — generation, distribution, storage, rotation, and revocation — and weak practices anywhere in that lifecycle can undermine otherwise strong cryptography.

Avatar Of Asad Ijaz

Lead Networking Architect and Editor at NetworkUstad. BS in Computer Networks and Security, CCNP and CCNA certified, with 11+ years of experience in enterprise network design, implementation, and troubleshooting. Writes practical tutorials on routing, IPv4 management, network automation, and security fundamentals.