350-201 exam dumps

350-201 practice question 82 of 289

Cybersecurity Professional - Performing Cybersecurity Using Cisco Security Technologies. Professional level, Cisco. Free question with the correct answer and a full explanation.

350-201 Question 82

Select 4

Your organization has recently experienced a security breach caused by attackers exploiting unused open ports and insecure protocols on your network infrastructure. As a cybersecurity engineer, you are tasked with hardening the network. Which of the following controls should you implement to enhance network security and prevent such breaches?

  1. A

    Disable unused ports and services on all network devices

  2. B

    Implement access control lists (ACLs) to restrict traffic based on source and destination

  3. C

    Enable Telnet for remote device management on network equipment

  4. D

    Configure network segmentation using VLANs to isolate sensitive assets

  5. E

    Allow unrestricted outbound traffic to ensure smooth business operations

  6. F

    Regularly update device firmware and apply security patches

Show answer and explanation

Correct answers: A, B, D, F

Explanation

Network hardening involves implementing controls to reduce vulnerabilities and mitigate risks. Disabling unused ports and services, using ACLs, configuring network segmentation, and applying security updates are key practices to enhance network security. Avoiding insecure protocols like Telnet and restricting outbound traffic are also essential to prevent breaches.

  • A. Correct.

    Disabling unused ports and services minimizes the attack surface by closing entry points that attackers might exploit. This is a critical step in network hardening.

  • B. Correct.

    Access control lists (ACLs) enforce traffic restrictions based on predefined policies, which reduces the risk of unauthorized access or data exfiltration.

  • C. Incorrect.

    Telnet is an insecure protocol that transmits data, including credentials, in plaintext. Using Telnet increases the likelihood of interception by attackers.

  • D. Correct.

    Network segmentation with VLANs isolates sensitive assets, limiting their exposure to potential attackers and containing the impact of breaches.

  • E. Incorrect.

    Allowing unrestricted outbound traffic can expose the network to data exfiltration and malware communication. Outbound traffic should be controlled to prevent these risks.

  • F. Correct.

    Regularly updating device firmware and applying patches addresses known vulnerabilities, ensuring that devices are protected against recent exploits.

Timed practice exam

Take a 350-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam