Soru

Zorluk: ZorNetwork Device Hardening Best Practices

Following an internal security audit of enterprise network infrastructure, a network engineer must remediate vulnerabilities on several Layer 3 switches. The audit report specifically highlighted risks associated with management plane traffic eavesdropping and VLAN hopping exploits on trunk links. Which of the following TWO device hardening measures should the engineer implement to directly address these findings? (Select TWO.)

  1. Configure SNMPv3 using the authPriv security mode to enforce cryptographic authentication and message payload encryption.Cevap
  2. Reassign the 802.1Q native VLAN on trunk links from the default VLAN 1 to an explicit, unused VLAN ID.Cevap
  3. C
    Implement SNMPv2c with complex read-only community strings to encrypt management polling traffic across trunk connections.
  4. D
    Assign all unused switch ports to native VLAN 1 and maintain their administrative state as enabled for rapid device provisioning.
  5. E
    Migrate administrative sessions to Telnet using port 22 to guarantee encrypted command-line management.

Cevap

The correct hardening actions are enabling SNMPv3 with authPriv for encrypted telemetry and reassigning the native VLAN on 802.1Q trunk links to an unused VLAN ID.
Hardening network switches against eavesdropping and trunk link attacks requires securing both management protocols and Layer 2 interfaces. Configuring SNMPv3 with the authPriv setting ensures authentication and full payload encryption for management communications. Furthermore, reassigning the native VLAN from default VLAN 1 to an unused VLAN ID prevents attacker frames from jumping broadcast domains via 802.1Q double-tagging.

Adım Adım Çözüm

1
Analyze management plane security requirements
Identify that SNMPv3 authPriv provides both authentication and payload privacy (encryption), unlike unencrypted SNMPv1/v2c.
Management plane protocols must prevent unauthorized access and credential/data interception.
2
Analyze trunk link vulnerability mitigations
Identify that changing the default native VLAN (VLAN 1) to a dedicated, unused VLAN ID prevents VLAN hopping exploits.
Crafted double-tagged 802.1Q frames rely on the native VLAN matching between switches to cross VLAN boundaries.
3
Evaluate distractor controls
Reject SNMPv2c, leaving unused ports in default VLAN 1, and Telnet on port 22 as insecure or incorrect implementations.
Insecure defaults and incorrect protocol choices introduce security vulnerabilities.

Anahtar Kavram

Management plane protocol encryption and Layer 2 trunk baseline security
Tahmini Süre:2m 0s
Bu soruyu puanla