nerdexam
Cisco

200-301 · Question #642

Which two practices are recommended for an acceptable security posture in a network? (Choose two)

The correct answer is B. Maintain network equipment in a secure location E. Disable unused or unnecessary ports, interfaces and services. Maintaining network equipment in a physically secure location and disabling unused ports, interfaces, and services are two fundamental practices for improving network security posture.

Submitted by carter_n· Mar 5, 2026Security Fundamentals

Question

Which two practices are recommended for an acceptable security posture in a network? (Choose two)

Options

  • ABackup device configurations to encrypted USB drives for secure retrieval
  • BMaintain network equipment in a secure location
  • CUse a cryptographic keychain to authenticate to network devices
  • DPlace internal email and file servers in a designated DMZ
  • EDisable unused or unnecessary ports, interfaces and services

How the community answered

(22 responses)
  • A
    14% (3)
  • B
    77% (17)
  • C
    5% (1)
  • D
    5% (1)

Why each option

Maintaining network equipment in a physically secure location and disabling unused ports, interfaces, and services are two fundamental practices for improving network security posture.

ABackup device configurations to encrypted USB drives for secure retrieval

While backing up configurations is good, relying solely on encrypted USB drives for secure retrieval isn't a universally recommended enterprise practice, as centralized, robust backup systems are generally preferred.

BMaintain network equipment in a secure locationCorrect

Maintaining network equipment in a secure physical location (e.g., locked server rooms, restricted access) prevents unauthorized physical access, which is a critical security control to protect against tampering and data theft.

CUse a cryptographic keychain to authenticate to network devices

Using a cryptographic keychain is a specific method for secure authentication between devices, not a broad security posture practice equivalent to physical security or attack surface reduction.

DPlace internal email and file servers in a designated DMZ

Placing internal email and file servers in a DMZ is generally a poor security practice; DMZs are for services exposed to untrusted networks, while internal servers should be in the internal network behind appropriate firewalls.

EDisable unused or unnecessary ports, interfaces and servicesCorrect

Disabling unused or unnecessary ports, interfaces, and services reduces the attack surface of network devices, minimizing potential entry points and vulnerabilities that attackers could exploit.

Concept tested: Network security best practices

Source: https://www.cisco.com/c/en/us/solutions/small-business/resource-center/secure-your-network/network-security-best-practices.html

Topics

#Physical security#Network hardening

Community Discussion

No community discussion yet for this question.

Full 200-301 Practice