220-802 · Question #159
A technician recently setup a new wired network and wants to ensure only their computers can use it. Which of the following is the MOST secure way to accomplish this?
The correct answer is D. Disable the extra ports on the router. Disabling unused switch or router ports prevents unauthorized physical devices from gaining any network access at all.
Question
A technician recently setup a new wired network and wants to ensure only their computers can use it. Which of the following is the MOST secure way to accomplish this?
Options
- AMake sure the computers are using strong passwords.
- BEnable an intrusion detection system.
- CAssign the computers static IP addresses.
- DDisable the extra ports on the router.
How the community answered
(37 responses)- A3% (1)
- B5% (2)
- C8% (3)
- D84% (31)
Why each option
Disabling unused switch or router ports prevents unauthorized physical devices from gaining any network access at all.
Strong passwords protect accounts but do not prevent an unauthorized computer from physically plugging in and accessing the network.
An intrusion detection system monitors and alerts on suspicious traffic but does not block an unauthorized device from initially connecting.
Static IP addresses do not prevent an unauthorized device from using an unconfigured IP address to access the network.
Disabling unused ports on a router or switch at the physical layer means an unauthorized device cannot obtain network connectivity even if physically present. This is the most secure option because it eliminates the attack surface entirely rather than relying on credentials, software detection, or IP assignment alone.
Concept tested: Physical port security on network switches and routers
Source: https://www.cisco.com/c/en/us/support/docs/lan-switching/spanning-tree-protocol/10556-42.html
Topics
Community Discussion
No community discussion yet for this question.