300-430 exam dumps

300-430 practice question 307 of 324

Implementing Cisco Enterprise Wireless Networks. Professional level, Cisco. Free question with the correct answer and a full explanation.

300-430 Question 307

Select 3

You are tasked with securing a Cisco wireless LAN controller (WLC) in a large enterprise network. Which of the following actions would be considered best practices for device hardening to mitigate security threats?

  1. A

    Disable unused ports and interfaces on the WLC.

  2. B

    Use a default SNMP community string for easier monitoring.

  3. C

    Enable HTTPS and disable HTTP for GUI management access.

  4. D

    Allow unrestricted access to the WLC from all IP addresses.

  5. E

    Implement role-based access control (RBAC) for administrative users.

  6. F

    Enable Telnet for device management to simplify connectivity.

Show answer and explanation

Correct answers: A, C, E

Explanation

Device hardening is critical for securing Cisco wireless LAN controllers. Best practices include reducing the attack surface by disabling unused interfaces, using secure management protocols like HTTPS, and implementing role-based access control to limit user permissions. Avoid insecure configurations such as default SNMP community strings, unrestricted access, and insecure management protocols like Telnet.

  • A. Correct.

    Disabling unused ports and interfaces reduces the attack surface of the WLC and prevents unauthorized access to the device.

  • B. Incorrect.

    Using a default SNMP community string is insecure because attackers can easily guess and exploit it to gain unauthorized access.

  • C. Correct.

    Enabling HTTPS and disabling HTTP ensures secure communication between administrators and the WLC, reducing the risk of credential theft or man-in-the-middle attacks.

  • D. Incorrect.

    Allowing unrestricted access to the WLC is a poor practice because it exposes the device to unauthorized access from untrusted sources.

  • E. Correct.

    Implementing role-based access control (RBAC) ensures that users only have the permissions necessary for their roles, which improves security by limiting access to critical functions.

  • F. Incorrect.

    Enabling Telnet is insecure because it transmits data, including credentials, in plaintext. SSH should be used instead for secure management.

Timed practice exam

Take a 300-430 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam