300-425 Question 125
Single answerYou are managing a Cisco wireless network and have enabled rogue detection to enhance network security. During a routine scan, the wireless controller identifies a rogue access point (AP) that appears to be connected to the network. What is the most appropriate next step to mitigate the risk associated with this rogue AP?
- A
Mark the rogue AP as 'Friendly' in the controller to avoid future alerts.
- B
Perform a containment action to prevent clients from connecting to the rogue AP.
- C
Disconnect the rogue AP from the network by deactivating its switch port.
- D
Ignore the alert for now and monitor the rogue AP for any suspicious activity.
Show answer and explanation
Correct answer: C
Explanation
When a rogue AP is identified as connected to the network, it poses an immediate security threat. The first action should be to mitigate the risk by disconnecting it from the network, typically by deactivating its switch port. This ensures that the rogue AP cannot facilitate unauthorized access to the network while further investigation is conducted.
- A. Incorrect.
Marking the rogue AP as 'Friendly' without verification could lead to a security breach if the rogue AP is indeed malicious.
- B. Incorrect.
Performing a containment action should only be done after confirming the rogue AP poses a threat and containment is legally permissible. It is not the first step.
- C. Correct.
Disconnecting the rogue AP from the network by deactivating its switch port is the most appropriate action to immediately mitigate risk and prevent unauthorized access to the network.
- D. Incorrect.
Ignoring the alert and monitoring the rogue AP allows potential unauthorized access to continue, which is not a recommended action.