300-425 exam dumps

300-425 practice question 308 of 324

Designing Cisco Enterprise Wireless Networks. Professional level, Cisco. Free question with the correct answer and a full explanation.

300-425 Question 308

Select 4

A network administrator is tasked with improving the security of a Cisco wireless infrastructure. They have been asked to implement device hardening on the wireless LAN controllers (WLCs). Which of the following actions should they prioritize to enhance the security of the WLCs?

  1. A

    Disable unused management interfaces such as HTTP and Telnet.

  2. B

    Enable SNMPv1 for backward compatibility with older monitoring tools.

  3. C

    Configure access control lists (ACLs) to restrict management access to trusted IP subnets.

  4. D

    Use a default administrative username and password for ease of access.

  5. E

    Enable HTTPS and disable HTTP for secure web-based management.

  6. F

    Apply firmware updates and patches as soon as they are released.

Show answer and explanation

Correct answers: A, C, E, F

Explanation

Device hardening involves implementing security measures to reduce vulnerabilities. Actions such as disabling unused interfaces, configuring ACLs, using secure protocols (e.g., HTTPS), and keeping firmware up-to-date are key best practices. Avoid insecure configurations like SNMPv1 or default credentials, as they expose the device to potential exploitation. By following these practices, the WLCs' security posture is significantly improved.

  • A. Correct.

    Disabling unused management interfaces like HTTP and Telnet reduces the attack surface and prevents unauthorized access using insecure protocols.

  • B. Incorrect.

    SNMPv1 is insecure as it uses plaintext community strings. It should be avoided in favor of SNMPv3, which provides encryption and authentication.

  • C. Correct.

    Configuring ACLs to restrict management access ensures that only authorized devices from trusted IP subnets can manage the WLCs.

  • D. Incorrect.

    Using default administrative credentials is a significant security risk, as they are easily guessable and commonly known.

  • E. Correct.

    Enabling HTTPS ensures secure communication for web-based management, while disabling HTTP prevents insecure access.

  • F. Correct.

    Applying firmware updates and patches addresses known vulnerabilities and ensures the WLCs are protected against the latest threats.

Timed practice exam

Take a 300-425 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam