Soru

Zorluk: KolayNetwork Device Hardening Best Practices

During a routine security audit, a systems engineer notices that remote administration sessions to a core network switch transmit credentials in plaintext. Which administrative change should be implemented to secure interactive command-line access to the switch?

  1. Enable SSH and disable Telnet on the switch management interface.Cevap
  2. B
    Enable HTTP web access on TCP port 80 to manage switch settings.
  3. C
    Configure SNMPv1 read-write community strings for command-line access.
  4. D
    Assign all management sessions to communicate over untagged native VLAN frames.

Cevap

Enable SSH and disable Telnet on the switch management interface.
Replacing Telnet with SSH ensures all management sessions are cryptographically secured using TCP port 22. SSH encrypts administrative credentials and commands, preventing eavesdropping and packet capture attacks across the network.

Adım Adım Çözüm

1
Identify the security vulnerability in the current remote management configuration.
The current remote administration protocol transmits credentials and commands in cleartext.
Telnet operates on TCP port 23 without cryptographic protection, leaving sessions vulnerable to packet sniffing.
2
Select the industry standard encrypted protocol for interactive command-line management.
SSH (Secure Shell) provides confidentiality and integrity using strong payload encryption over TCP port 22.
Hardening switch management requires disabling legacy cleartext services in favor of secure, encrypted alternatives.

Anahtar Kavram

Device Hardening via Secure Management Protocols
Tahmini Süre:45s
Bu soruyu puanla