200-301 · Question #99
An engineer is asked to protect unused ports that are configured in the default VLAN on a switch. Which two steps will fulfill the request? (Choose two)
The correct answer is B. Administratively shut down the ports C. Configure the port type as access and place in VLAN 99. To secure unused switch ports, an engineer should administratively shut them down and reassign them to an isolated, unused VLAN.
Question
Options
- AConfigure the ports in an EtherChannel.
- BAdministratively shut down the ports
- CConfigure the port type as access and place in VLAN 99
- DConfigure the ports as trunk ports
- EEnable the Cisco Discovery Protocol
How the community answered
(32 responses)- A3% (1)
- B84% (27)
- D3% (1)
- E9% (3)
Why each option
To secure unused switch ports, an engineer should administratively shut them down and reassign them to an isolated, unused VLAN.
Configuring ports in an EtherChannel bundles them for increased bandwidth and redundancy, which does not secure individual unused ports.
Administratively shutting down unused ports prevents any device from connecting to them and gaining network access, effectively disabling the port physically and logically.
Moving unused ports to an isolated, unused VLAN (e.g., VLAN 99) separates them from active network segments, preventing unauthorized devices from accessing network resources even if they are physically connected.
Configuring ports as trunk ports allows multiple VLANs to traverse them, which increases the attack surface for unused ports rather than securing them.
Enabling Cisco Discovery Protocol (CDP) allows device discovery but is not a security measure for unused ports and can potentially expose information about the switch.
Concept tested: Securing unused switch ports
Source: https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst3560/software/release/12-2_55_se/configuration/guide/3560scg/swint.html#wp1077651
Topics
Community Discussion
No community discussion yet for this question.