A network specialist is auditing and hardening newly deployed Layer 2 access switches at a branch office. To minimize the local physical attack surface and prevent VLAN hopping attacks across trunk connections, which TWO hardening practices should the specialist implement? (Select TWO.)
- Assign all unused physical switch ports to an unused blackhole VLAN and administratively disable them.Answer
- BKeep all unused physical switch ports active in the default VLAN to streamline future device onboarding.
- Change the native VLAN on 802.1Q trunk links from the default VLAN to an unused VLAN ID.Answer
- DSet the native VLAN on trunk links to match the active management VLAN to allow untagged administrative traffic.
- EEnable Telnet over TCP port 22 and HTTP over TCP port 443 across management interfaces for remote access.
Answer
The specialist should assign all unused physical switch ports to an unused blackhole VLAN while administratively shutting them down, and change the native VLAN on 802.1Q trunk links from the default VLAN to a dedicated, unused VLAN ID.
Hardening switch interfaces requires securing unused access ports by assigning them to a non-routable blackhole VLAN and disabling them, as well as mitigating VLAN hopping by changing the default native VLAN on 802.1Q trunk interfaces to an unused VLAN ID.
Step-by-Step Solution
Key Concept
Switch Port Security and Native VLAN Hardening
Estimated Time:1m 30s