During a baseline security audit of an enterprise network infrastructure, a systems administrator discovers an operational network switch that is still functioning with factory-assigned administrative username and password credentials. Which of the following best classifies this host and infrastructure security weakness?
- Default configuration vulnerabilityAnswer
- BPerimeter-based implicit trust assumption
- CCross-site scripting application vulnerability
- DNetwork firewall access control rule failure
Answer
Default configuration vulnerability
The correct answer highlights a default configuration vulnerability. Manufacturers ship networking equipment with standard, publicly documented credentials to allow initial setup. Failing to change these default settings during system hardening exposes the host or infrastructure device to trivial exploitation by attackers.
Step-by-Step Solution
Key Concept
Default Configurations in Host and Infrastructure Hardening