SY0-701 exam dumps

SY0-701 practice question 74 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 74

Single answerUnsecure networks: Wireless , Wired , Bluetooth , Open service ports , Default credentials

A security administrator is reviewing a small branch office after a recent penetration test. The report shows three findings: an office printer is reachable over the network on TCP 23, the printer web console still uses the manufacturer's default admin password, and employees frequently pair personal Bluetooth headsets with company laptops. The administrator needs to reduce the most likely avenues for unauthorized access with the least disruption to business operations. Which action should the administrator take FIRST?

  1. A

    Disable Telnet on the printer, change the default administrator password, and manage the device using a secure protocol such as HTTPS or SSH if supported

  2. B

    Block all Bluetooth traffic on the firewall so personal headsets can no longer connect to company laptops

  3. C

    Replace the printer with a wired-only model that does not support wireless or Bluetooth connectivity

  4. D

    Move the printer to a different VLAN but leave its current management settings unchanged

Show answer and explanation

Correct answer: A

Explanation

This question tests prioritization of remediation for unsecured networked devices. In this scenario, the printer presents a clear and immediate risk because it exposes an insecure service port (TCP 23 for Telnet) and still uses default credentials. These two issues are commonly exploited in real environments and should be remediated before taking broader or more disruptive actions. Security best practices from sources such as NIST device hardening guidance and vendor security configuration recommendations consistently emphasize disabling unnecessary or insecure services, changing default passwords, and using encrypted management protocols. While Bluetooth use on company systems may warrant policy controls and segmentation can reduce overall exposure, neither is the best FIRST action compared with directly removing known exploitable weaknesses on the device.

  • A. Correct.

    Correct. The most immediate and practical risk is the combination of an open insecure management port and default credentials on a network-connected device. Telnet sends credentials and session data in cleartext, and default passwords are commonly abused in real attacks. Disabling Telnet and changing default credentials directly addresses two active weaknesses while preserving business functionality. Using secure management protocols such as HTTPS or SSH aligns with hardening best practices for embedded devices and network peripherals.

  • B. Incorrect.

    Incorrect. Bluetooth can increase attack surface, especially if unmanaged or paired with untrusted devices, but this option does not address the more critical and already confirmed vulnerabilities on the printer. Also, Bluetooth traffic between a laptop and a local headset would not typically be controlled by the network firewall in the way this option suggests, making it a less effective first step.

  • C. Incorrect.

    Incorrect. Replacing the printer may reduce some future risk, but it is not the least disruptive or most immediate corrective action. The existing exposure comes primarily from insecure management services and default credentials, both of which can usually be remediated quickly through configuration changes without replacing hardware.

  • D. Incorrect.

    Incorrect. Network segmentation can help limit lateral movement and reduce exposure, but leaving Telnet enabled and the default password unchanged means the core vulnerability remains exploitable by anyone who can still reach the device from that VLAN. Segmentation is a defense-in-depth measure, not the best first action when straightforward hardening issues are present.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam