Soru

Zorluk: KolayHost, Network, and Architecture Vulnerabilities

An IT technician is auditing an organization's legacy infrastructure to identify host and network vulnerabilities. Which TWO of the following technical conditions represent significant network or host architecture vulnerabilities that could allow unauthorized access or credential exposure? (Select TWO.)

  1. Using cleartext management protocols such as Telnet and HTTP for system administrationCevap
  2. Running unpatched end-of-life firmware on perimeter routers with known remote code execution flawsCevap
  3. C
    Configuring network-level firewalls to block incoming requests targeted at database application ports
  4. D
    Deploying WPA3-Enterprise encryption across corporate wireless access points
  5. E
    Enforcing Zero Trust continuous authentication for internal microsegmented network subnets

Cevap

Using cleartext management protocols (such as Telnet and HTTP) and running unpatched end-of-life firmware on perimeter routers represent significant host and network architecture vulnerabilities.
Cleartext protocols (such as Telnet and HTTP) transmit sensitive authentication credentials unencrypted across the network, enabling passive sniffing attacks. Additionally, unpatched end-of-life router firmware leaves known remote code execution vulnerabilities unmitigated, allowing remote exploitation.

Adım Adım Çözüm

1
Analyze each option to determine if it represents a vulnerability or a defensive security control.
Identified cleartext protocols and unpatched router firmware as vulnerable security weaknesses.
Cleartext protocols expose network data to interception, and unpatched firmware provides known exploit paths for attackers.
2
Differentiate defensive controls from infrastructure security weaknesses.
Confirmed firewall filtering, WPA3 wireless encryption, and Zero Trust microsegmentation are security controls, not vulnerabilities.
These controls mitigate threats and protect architecture rather than exposing systems to risk.

Anahtar Kavram

Host, Network, and Architecture Vulnerabilities
Bu soruyu puanla