350-201 exam dumps

350-201 practice question 75 of 289

Cybersecurity Professional - Performing Cybersecurity Using Cisco Security Technologies. Professional level, Cisco. Free question with the correct answer and a full explanation.

350-201 Question 75

Select 4

Your organization has deployed a new Cisco ASA firewall to secure a branch office. After the initial deployment, you notice that several default services are running which are not required for the branch's operations. Which services should you recommend disabling to reduce the attack surface of the firewall?

  1. A

    Telnet access to the firewall

  2. B

    HTTP management interface

  3. C

    SSH access to the firewall

  4. D

    ICMP unreachable message generation

  5. E

    FTP server on the firewall

  6. F

    SNMPv3 service

Show answer and explanation

Correct answers: A, B, D, E

Explanation

To reduce the attack surface of a Cisco ASA firewall, it is essential to disable unnecessary or insecure services. Telnet and HTTP are insecure protocols and should be disabled in favor of secure alternatives like SSH and HTTPS. Services like ICMP unreachable messages and FTP are also commonly unnecessary for branch office operations and could be exploited by attackers if left enabled. SNMPv3, when configured securely, can remain enabled if required for monitoring.

  • A. Correct.

    Telnet is an insecure protocol that transmits data, including credentials, in plaintext. It should be disabled to prevent unauthorized access to the firewall.

  • B. Correct.

    The HTTP management interface is less secure compared to HTTPS and could expose sensitive management functions. Disabling HTTP in favor of HTTPS is recommended.

  • C. Incorrect.

    SSH is a secure protocol for remote management and should remain enabled to allow secure administrative access.

  • D. Correct.

    ICMP unreachable messages can provide information about the network to attackers, such as topology or reachable hosts. Disabling this reduces the risk of reconnaissance.

  • E. Correct.

    An FTP server on the firewall is unnecessary unless specifically required, and it is inherently insecure. It should be disabled to prevent exploitation.

  • F. Incorrect.

    SNMPv3 is a secure protocol for network management. If configured properly and required for monitoring, it can remain enabled.

Timed practice exam

Take a 350-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam