Network switch
A layer 2 device that forwards frames to the port where the destination MAC address was learned, instead of repeating every frame to every port as a hub does.
A network switch connects devices on a local network, forwarding frames at layer 2 of the OSI model. It learns which MAC address sits behind each port by reading the source address of incoming frames, stores that in a MAC address table, and sends each frame only to the port that leads to its destination. Frames for an unknown destination, and broadcasts, are flooded to every other port in the same VLAN. A layer 3 switch adds routing between VLANs, which blurs the line with a router. Switches forward either store-and-forward or cut-through.
The comparison candidates are expected to make is with a hub, which repeats every frame to every port. Because a switch delivers traffic only where it belongs, a host does not normally see other hosts’ unicast traffic, which makes packet sniffing harder. That protection can be undone: MAC flooding fills the address table so the switch floods frames it can no longer place, and ARP spoofing redirects traffic through an attacker. Port security and IEEE 802.1X, with the switch as authenticator, are the usual port controls.
Exam relevance: questions in this area tend to turn on the layer at which a device works and what it forwards. A scenario about a switch suddenly behaving like a hub is likely to point to MAC flooding.