Soru

Zorluk: KolayNetwork Device Hardening Best Practices

A network technician is preparing to deploy a new switch into a production environment. Which TWO of the following security configuration steps represent essential device hardening best practices for securing administrative management access? (Select TWO.)

  1. Disable Telnet and mandate the use of SSH version 2 for remote command-line administrative sessionsCevap
  2. B
    Use unencrypted HTTP for the web interface to minimize processing overhead on the switch CPU
  3. Change default administrative credentials and implement strong password policiesCevap
  4. D
    Enable SNMPv1 with default community strings to simplify remote system monitoring
  5. E
    Assign all unused physical switch ports to the active native VLAN to simplify network provisioning

Cevap

Disabling cleartext protocols like Telnet in favor of SSH version 2 and replacing default administrative login credentials with strong passwords are primary network device hardening controls.
Device hardening on network equipment prioritizes securing administrative access. Disabling Telnet in favor of SSH version 2 ensures management commands and credentials are cryptographically encrypted. Changing default administrative usernames and establishing complex passwords prevents unauthorized users from easily guessing factory default login parameters.

Adım Adım Çözüm

1
Identify insecure management protocols
Recognize that cleartext management protocols (such as Telnet, HTTP, and SNMPv1) expose management traffic to interception and must be replaced with encrypted equivalents.
Securing the management plane requires encryption of credentials and administrative commands in transit.
2
Identify authentication hardening requirements
Recognize that default accounts and credentials must be updated immediately upon switch deployment.
Default credentials are widely documented and represent a severe security vulnerability if left unchanged.

Anahtar Kavram

Network Device Hardening Best Practices
Bu soruyu puanla