300-430 exam dumps

300-430 practice question 305 of 324

Implementing Cisco Enterprise Wireless Networks. Professional level, Cisco. Free question with the correct answer and a full explanation.

300-430 Question 305

Select 3

An enterprise network administrator is tasked with improving the security of their Cisco wireless infrastructure by hardening the devices. The administrator decides to focus on management access to the wireless LAN controller (WLC). Which of the following actions should the administrator take to achieve this?

  1. A

    Disable unused management interfaces such as HTTP and Telnet on the WLC.

  2. B

    Enable HTTPS and SSH for secure management access to the WLC.

  3. C

    Use the default administrator username and password to simplify access during emergencies.

  4. D

    Configure role-based access control (RBAC) to assign appropriate privileges to administrators.

  5. E

    Enable SNMPv1 for monitoring the WLC to ensure backward compatibility with older tools.

Show answer and explanation

Correct answers: A, B, D

Explanation

Device hardening involves minimizing the attack surface and securing management access to prevent unauthorized access or interception of sensitive data. Disabling insecure or unused interfaces, enabling encrypted protocols like HTTPS/SSH, and implementing RBAC are essential steps to achieve this. Default credentials and insecure protocols like SNMPv1 should always be avoided to maintain a secure wireless network environment.

  • A. Correct.

    Disabling unused management interfaces like HTTP and Telnet reduces the attack surface and prevents the use of insecure protocols. This is a best practice for device hardening.

  • B. Correct.

    Enabling HTTPS and SSH ensures that management traffic is encrypted, protecting sensitive data such as credentials from being intercepted.

  • C. Incorrect.

    Using default credentials is a critical security risk and should be avoided. Custom, strong passwords should always be configured.

  • D. Correct.

    Configuring RBAC ensures that administrators have only the privileges they need, reducing the likelihood of accidental or intentional misuse of administrative capabilities.

  • E. Incorrect.

    SNMPv1 is an insecure protocol that transmits data in plain text. SNMPv3 should be used for secure monitoring.

Timed practice exam

Take a 300-430 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam