A security audit of an organization's internal infrastructure reveals two major compliance failures: administrative credentials and configuration data are being transmitted in cleartext across management subnets, and active administrative sessions on management consoles remain authenticated indefinitely without user activity. Which of the following enterprise hardening practices should the security team implement to directly address these findings? (Select TWO.)
- Disable unencrypted management protocols such as HTTP, Telnet, and SNMPv1/v2 in favor of encrypted alternatives like HTTPS and SSHv2.Cevap
- Configure mandatory session timeouts and re-authentication requirements on all administrative web interfaces.Cevap
- CDeploy perimeter intrusion prevention systems (IPS) to detect cleartext administrative traffic entering the corporate network.
- DImplement production honeypots configured to inline filter cleartext management requests before reaching internal routers.
Cevap
Disabling unencrypted management protocols in favor of SSHv2/HTTPS and enforcing mandatory session timeouts on administrative interfaces directly mitigate cleartext credential exposure and persistent unmonitored administrative sessions.
Disabling legacy cleartext protocols (HTTP, Telnet, SNMPv1/v2) and replacing them with encrypted protocols ensures confidentiality of credentials in transit. Implementing session timeouts ensures inactive administrative web sessions are closed, mitigating unauthorized access to unattended sessions.
Adım Adım Çözüm
Anahtar Kavram
Enterprise Hardening and Secure Service Management
Tahmini Süre:1m 30s