350-201 exam dumps

350-201 practice question 84 of 289

Cybersecurity Professional - Performing Cybersecurity Using Cisco Security Technologies. Professional level, Cisco. Free question with the correct answer and a full explanation.

350-201 Question 84

Select 3

An organization has recently experienced a network breach due to unauthorized access. As a cybersecurity specialist, you are tasked with implementing network controls to harden the organization's network. Which of the following actions should you take to improve the network's security posture?

  1. A

    Segment the network using VLANs to isolate critical systems from general user traffic.

  2. B

    Disable unused network ports on switches to reduce the attack surface.

  3. C

    Implement a single flat network to simplify traffic monitoring and reduce complexity.

  4. D

    Enforce the use of port security to limit devices that can connect to the network.

  5. E

    Allow unrestricted access to all internal resources from any subnet to enhance connectivity.

Show answer and explanation

Correct answers: A, B, D

Explanation

Network hardening involves implementing controls that reduce vulnerabilities and limit unauthorized access. Actions such as network segmentation, disabling unused ports, and enforcing port security are key strategies for improving network security. Avoiding practices like using a flat network or allowing unrestricted access ensures reduced attack surfaces and better control over potential threats.

  • A. Correct.

    Segmenting the network using VLANs is a best practice for isolating sensitive systems, limiting the spread of attacks, and improving overall network security.

  • B. Correct.

    Disabling unused network ports reduces the attack surface by preventing unauthorized devices from connecting to the network.

  • C. Incorrect.

    Implementing a single flat network increases the risk of lateral movement by attackers and does not align with hardening principles.

  • D. Correct.

    Port security enforces strict control over which devices can connect to the network, thereby reducing the risk of unauthorized access.

  • E. Incorrect.

    Unrestricted access to internal resources is a significant security risk and violates the principle of least privilege.

Timed practice exam

Take a 350-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam