Domain 4.0 | Network Security — 14% of exam
Learning Objectives
By the end of this lesson, you will be able to:
- Explain device hardening practices, including disabling unused ports/services and changing default passwords
- Describe port security as a Layer 2 defense against MAC-based attacks
- Explain 802.1X as a network access control framework
- Describe MAC filtering and its real-world limitations
- Explain key management and why it matters for cryptographic security
Key Terms
| Term | Definition |
|---|---|
| Device Hardening | Reducing a device’s attack surface by disabling unnecessary services, closing unused ports, and changing default credentials |
| Port Security | A switch feature limiting which or how many MAC addresses are allowed on a given port |
| 802.1X | A network access control framework requiring authentication before a device is granted network access |
| MAC Filtering | Restricting network access based on an allow or deny list of MAC addresses |
| Key Management | The secure generation, distribution, storage, rotation, and revocation of cryptographic keys |
Explanation
From Attack Types to Defense
Objective 4.2 covered specific attack techniques in detail — MAC flooding, ARP poisoning, on-path attacks, and rogue devices and evil twins. This lesson covers concrete defenses, several of which map directly onto attacks already covered — port security exists specifically to prevent MAC flooding, and 802.1X exists specifically to prevent unauthorized rogue devices from simply plugging in and gaining network access.Device Hardening: Reducing the Attack Surface
Device hardening is the general practice of reducing a device’s attack surface — the total set of ways it could potentially be compromised — by eliminating anything unnecessary:
Disabling unused ports and services removes potential entry points entirely. Every open port or running service represents a possible vulnerability waiting to be discovered; a service that isn’t running at all can’t be exploited, regardless of whether a vulnerability in it is ever found.Changing default passwords addresses one of the most common and easily avoidable security failures. Default credentials for common device models are widely known and often published online — leaving a default password unchanged is essentially the same as having no password-based access control at all, since anyone who knows (or looks up) the default can walk right in.
Neither practice is glamorous or technically sophisticated, but both dramatically reduce the number of easy, low-effort attack paths available against a device.
Port Security: A Layer 2 Defense Against MAC Flooding
Port security is a switch feature that directly addresses the MAC flooding attack covered in the previous objective: by limiting the number of MAC addresses allowed on a given port — or restricting a port to one or a few specifically known, permitted addresses — port security prevents an attacker from ever successfully overwhelming the switch’s MAC table in the first place. When a port security violation occurs (too many MAC addresses observed, or an unrecognized MAC on a restricted port), the switch can be configured to take action — shutting the port down, restricting further learning, or simply logging the event.

802.1X: Network Access Control at the Port Level
802.1X takes network access control further, requiring a device to successfully authenticate before it’s granted any meaningful network access at all — not just limiting which MAC addresses are allowed, but actually verifying identity before opening the port up for regular traffic. 802.1X typically works alongside a backend authentication server — commonly RADIUS, covered earlier in this module — which the switch or access point consults to actually verify the connecting device or user’s credentials.
This is exactly the mechanism that prevents the kind of casual rogue device scenario covered earlier — an unauthorized device (or a well-meaning employee’s personal access point) simply plugging into an open switch port and immediately gaining network access. With 802.1X properly enforced, an unauthenticated device connecting to that port gets essentially nothing until it successfully proves its identity.
MAC Filtering and Its Limitations
MAC filtering restricts network access based on a list of allowed or denied MAC addresses — conceptually simple, and available on nearly every consumer and enterprise wireless access point. The significant limitation is that MAC addresses can be trivially spoofed: an attacker who observes a permitted MAC address on the network (which isn’t difficult, since MAC addresses are visible in plain traffic) can simply configure their own device to present that same address, defeating the filter entirely. MAC filtering is still commonly used as one layer of defense, but it should never be relied upon as a strong, standalone access control — 802.1X’s actual authentication provides meaningfully stronger protection.
Key Management
Key management covers the full lifecycle of cryptographic keys: secure generation, controlled distribution to only the parties who legitimately need them, protected storage (recall from the PKI lesson that a private key must never leave its owner’s control), periodic rotation to limit the damage if a key is ever compromised, and prompt revocation when a key genuinely is compromised or an associated certificate needs to be invalidated.
Poor key management can undermine even a technically sound cryptographic system entirely — strong encryption built on a poorly protected or carelessly distributed key provides little real security, since the strength of the underlying algorithm matters far less than how well the actual key is protected in practice.
Recognition-Level Verification Concepts
A few patterns are worth recognizing on sight:
- A switch port configured to allow only one or two specific MAC addresses, shutting down if violated, is port security in action.
- A device unable to pass any meaningful traffic until it successfully authenticates against a RADIUS server describes 802.1X enforcement.
- An access point relying solely on an allow-list of MAC addresses, with no further authentication, is using MAC filtering — a weaker control than it might initially appear.
- A described process covering how a cryptographic key is created, distributed, stored, and eventually retired describes key management as a whole lifecycle, not a single one-time action.
Common Exam Traps
- Port security and 802.1X are not the same mechanism, even though both operate at the switch port level. Port security is about MAC address quantity/identity; 802.1X is about actual authentication before granting access at all.
- MAC filtering is a genuinely weak control on its own, since MAC addresses are trivially spoofable. Don’t treat it as equivalent in strength to real authentication mechanisms like 802.1X.
- Disabling unused ports and services is a preventive measure, not a reactive one. It reduces the attack surface before an attack is even attempted, rather than responding to one already underway.
- An unchanged default password isn’t a weak security control — it’s effectively no security control at all, given how widely known default credentials typically are.
- Key management is a full lifecycle, not a single event. Generation alone, without proper distribution, storage, rotation, and revocation practices, leaves real gaps even for otherwise strong cryptography.
Lesson 4.3.1 Practice Quiz — Device Hardening & Network Access Control
17 questions covering device hardening, port security, 802.1X, MAC filtering, and key management.
N10-009 · Domain 4.3Summary
Device hardening reduces attack surface by disabling unused ports and services and changing default credentials — simple practices that eliminate easy, low-effort attack paths.
Port security limits the number or identity of MAC addresses allowed on a switch port, directly preventing MAC flooding attacks.
802.1X requires actual authentication, typically against a backend RADIUS server, before granting meaningful network access, directly preventing casual rogue device connections.
MAC filtering restricts access by MAC address but is easily defeated through spoofing, making it a weak standalone control compared to genuine authentication.
Key management covers the full lifecycle of cryptographic keys — generation, distribution, storage, rotation, and revocation — and weak practices anywhere in that lifecycle can undermine otherwise strong cryptography.



