Soru

Zorluk: KolayNetwork Device Hardening Best Practices

A network technician is preparing a newly unboxed switch for deployment on a corporate network. Place the following administrative device hardening steps in the correct chronological order from first to last.

  1. 1Establish an out-of-band serial console connection to access the switch command-line interface.
  2. 2Change default administrative account passwords and create dedicated local user accounts.
  3. 3Generate cryptographic keys and enable SSH for remote management while disabling cleartext Telnet.
  4. 4Apply management Access Control Lists (ACLs) and administratively shut down all unused switch ports.

Cevap

The correct sequence begins with establishing an out-of-band serial console connection, followed by updating default administrative passwords, configuring SSH while disabling Telnet, and concluding with applying management Access Control Lists and shutting down unused ports.
Device hardening follows a logical sequence: first connecting directly via an out-of-band console cable, changing default passwords to secure administrative access, enabling encrypted SSH management while turning off unencrypted Telnet, and finally restricting network access with management ACLs and shutting down unused physical ports.

Adım Adım Çözüm

1
Establish out-of-band console access
Direct command-line interface access is established locally.
Initial setup must be performed out-of-band before remote access services or IP network interfaces exist.
2
Change default administrative credentials
Factory default usernames and passwords are removed and secured.
Default account credentials leave the switch vulnerable to unauthorized login if remote management is enabled.
3
Configure SSH and disable Telnet
Remote administrative communications are encrypted and unencrypted Telnet access is disabled.
Secure remote access requires crypto key generation and active user credentials before remote login can occur.
4
Apply management ACLs and disable unused ports
Unused physical ports are disabled and remote management is restricted to authorized subnets.
Restricting IP management access and turning off unused ports completes the baseline hardening phase.

Anahtar Kavram

Chronological Baseline Hardening Sequence for Network Switches
Tahmini Süre:1m 0s
Bu soruyu puanla