Soru

Zorluk: OrtaKey Security Concepts, Threats, Vulnerabilities, and Mitigations

A network engineering team is updating management access policies to reduce vulnerabilities associated with credential sniffing, brute-force access attempts, and unauthenticated administrative sessions across enterprise devices. Which two security controls directly mitigate these specific vulnerabilities and threats? (Select two.)

  1. Enforcing Secure Shell (SSH) for device management to encrypt access credentials and session data in transitCevap
  2. Implementing Multi-Factor Authentication (MFA) for administrative access to prevent unauthorized logins from compromised passwordsCevap
  3. C
    Configuring RADIUS authentication under the assumption that it encrypts the full body of every management command packet sent to switches
  4. D
    Applying standard access control lists to core router interfaces without explicit permit statements, expecting unlisted management traffic to pass automatically

Cevap

Enforcing SSH for device management and implementing Multi-Factor Authentication (MFA) for administrative access directly mitigate packet sniffing and credential-based unauthorized access.
Enforcing SSH encrypts administrative network traffic to prevent eavesdropping and credential theft in transit. Implementing Multi-Factor Authentication (MFA) adds a critical layer of defense ensuring that compromised administrative passwords alone cannot grant access to network devices.

Adım Adım Çözüm

1
Identify the threat vectors described in the scenario
The identified threat vectors are credential sniffing (packet eavesdropping), unauthorized access, and brute-force/compromised password usage.
Security controls must specifically target the operational mechanisms of the identified threats and vulnerabilities.
2
Evaluate the control that addresses packet sniffing of administrative sessions
SSH provides encrypted transport for remote management traffic, ensuring passwords and commands cannot be read in cleartext over the network.
Cleartext protocols like Telnet leave management sessions vulnerable to active and passive eavesdropping.
3
Evaluate the control that addresses weak or compromised administrative passwords
Multi-Factor Authentication requires a second independent credential factor (such as a time-based token or push notification), stopping attackers who obtain static passwords.
Password complexity alone is vulnerable to phishing and brute-force attacks without multi-factor verification.

Anahtar Kavram

Key Security Threats, Vulnerabilities, and Mitigations
Bu soruyu puanla