N10-009 exam dumps

N10-009 practice question 276 of 329

Network+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

N10-009 Question 276

Select 3

A company is preparing for a security audit after discovering that an unauthorized laptop was plugged into an open wall jack in a conference room and gained basic network connectivity. The network administrator also finds that several access switches still use vendor default credentials and that many switch ports in unused offices remain active. The company wants to prevent unauthorized devices from connecting in the future while minimizing disruption for employees who use domain-joined laptops. Which THREE actions should the administrator take to best harden the environment?

  1. A

    Implement 802.1X on access switch ports with a RADIUS server to authenticate endpoints before granting network access

  2. B

    Change the default administrative passwords on the switches and disable unused switch ports

  3. C

    Enable port security by limiting each active access port to the expected number of MAC addresses

  4. D

    Rely on MAC filtering alone because it provides strong device authentication without additional infrastructure

  5. E

    Leave unused ports enabled so employees can quickly move desks without requiring network changes

Show answer and explanation

Correct answers: A, B, C

Explanation

The best answer combines layered hardening controls: 802.1X for authentication-based network access control, changing default switch passwords to secure management access, disabling unused ports to reduce exposure, and port security to limit unexpected devices on active access ports. In practice, organizations commonly deploy 802.1X using the IEEE 802.1X standard with a RADIUS server for centralized authentication and authorization. Port security is a supplementary switch feature that helps enforce expected behavior on access ports but does not provide the same identity assurance as 802.1X. MAC filtering alone is weaker because MAC addresses can be spoofed, so it should not be the sole protection for enterprise access control. These recommendations align with common vendor hardening guidance and generally accepted security best practices such as removing default credentials, minimizing exposed services and interfaces, and enforcing authenticated network access.

  • A. Correct.

    This is correct. 802.1X is a standards-based network access control method that authenticates a device, user, or both before the switch port transitions from an unauthorized state to an authorized state. In an enterprise environment with domain-joined laptops, 802.1X paired with a RADIUS server is a common and practical control for preventing unauthorized systems from simply plugging into an open jack and gaining access.

  • B. Correct.

    This is correct. Changing default passwords is a basic but critical device-hardening step because vendor defaults are widely known and frequently targeted. Disabling unused switch ports reduces the attack surface by preventing someone from connecting to an unneeded active port in an empty office or conference room. Together, these directly address two weaknesses identified in the scenario.

  • C. Correct.

    This is correct. Port security can restrict the number of MAC addresses learned on an access port and can take action such as shutdown or restrict if unexpected devices appear. This helps limit casual unauthorized access and is especially useful on ports intended for a single workstation or a small known set of devices. While not a replacement for 802.1X, it is an additional hardening control aligned with the scenario.

  • D. Incorrect.

    This is incorrect. MAC filtering by itself is not considered strong authentication because MAC addresses can often be spoofed. It may provide limited administrative control in small or specialized environments, but relying on it alone would not be a best-practice solution for preventing unauthorized access in an enterprise audit scenario. A candidate might choose this because MAC-based controls sound device-specific, but they are weaker than 802.1X and NAC approaches.

  • E. Incorrect.

    This is incorrect. Leaving unused ports enabled increases the attack surface and directly contributed to the problem in the scenario. Although convenience for office moves is a real operational concern, security best practice is to disable unused ports and re-enable them through change control when needed. A candidate might choose this option because it reduces administrative effort, but it conflicts with device-hardening principles.

Timed practice exam

Take a N10-009 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam