712-50 exam dumps

712-50 practice question 300 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 300

Single answerIdentify the basic network architecture, models, protocols and components such as routers and hubs that play a role in network security

A newly acquired subsidiary has connected its office to the corporate network. During a post-acquisition review, the CISO learns that the subsidiary's user workstations and a small server segment are still connected through an unmanaged Ethernet hub, which uplinks to a router that connects back to headquarters. Security monitoring has identified signs of packet sniffing and intermittent unauthorized access to unencrypted internal application traffic. The CISO wants the first remediation step that most directly reduces this exposure without redesigning the entire WAN. Which action is the BEST recommendation?

  1. A

    Replace the hub with a managed Layer 2 switch and segment sensitive systems into separate VLANs with appropriate access controls

  2. B

    Upgrade the router firmware because routers prevent local packet capture on shared Ethernet segments

  3. C

    Increase the bandwidth of the WAN link to headquarters so suspicious traffic can be analyzed faster by central monitoring tools

  4. D

    Move the subsidiary's DNS service to headquarters because DNS centralization prevents internal sniffing of application traffic

Show answer and explanation

Correct answer: A

Explanation

The key risk in this scenario comes from using a hub rather than a switch. Hubs are legacy Layer 1 devices that repeat incoming traffic to all ports, making them inherently insecure for modern enterprise environments because they facilitate passive eavesdropping. In contrast, switches operate at Layer 2 and forward frames based on MAC address tables, significantly reducing indiscriminate traffic exposure. A managed switch also enables VLANs, which support segmentation and align with security best practices such as limiting broadcast domains and reducing unnecessary access paths. From a leadership and governance perspective, the CISO should prioritize remediation that addresses the root architectural weakness with the highest immediate risk reduction. This approach is consistent with widely accepted guidance from NIST and CIS Controls emphasizing network segmentation, least privilege, secure architecture, and replacement of insecure legacy components. While encryption of sensitive application traffic is also important, the BEST first step in this exact scenario is eliminating the hub-based shared segment and implementing managed switching with segmentation.

  • A. Correct.

    Correct. An Ethernet hub repeats traffic out all ports, creating a shared collision domain where any connected device can potentially capture traffic from other hosts. Replacing the hub with a managed switch reduces exposure by forwarding unicast frames only to the appropriate port, and VLAN segmentation further limits unnecessary Layer 2 adjacency between user systems and sensitive servers. Adding access controls between VLANs strengthens network security without requiring a full architectural redesign.

  • B. Incorrect.

    Incorrect. Updating router firmware is good operational hygiene and may address known vulnerabilities, but it does not solve the core issue in this scenario: a shared-media hub that allows local traffic exposure. Routers operate at Layer 3 and do not prevent sniffing that occurs on the same hub-based Layer 2 segment before traffic is routed.

  • C. Incorrect.

    Incorrect. More WAN bandwidth may improve performance or support centralized monitoring, but it does not address the fundamental network architecture weakness that enables packet capture inside the subsidiary office. The problem is local segment design, not link capacity.

  • D. Incorrect.

    Incorrect. Centralizing DNS may help with administration, visibility, or policy consistency, but DNS placement does not prevent hosts on a hub from observing broadcast and other shared-segment traffic. It does not materially mitigate sniffing of unencrypted internal application sessions.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam