nerdexam
CompTIA

220-802 · Question #356

A technician is tasked with improving the security of a SOHO network. The office is comprised of a single wireless router located under the front desk where the office manager sits. All desktop…

The correct answer is D. Place the router in a locked room. With strong credentials already configured and wireless already disabled, the remaining vulnerability is physical access to the router sitting in an unsecured location. Placing the router in a locked room addresses this gap.

Networking

Question

A technician is tasked with improving the security of a SOHO network. The office is comprised of a single wireless router located under the front desk where the office manager sits. All desktop computers are wired into the router which is configured with strong device credentials. Additionally, wireless is disabled on the router. Which of the following should the technician perform NEXT to improve the security of the SOHO network?

Options

  • ADisable the router's remote management feature.
  • BEnable WPA2 wireless encryption.
  • CChange the router's default admin name and password.
  • DPlace the router in a locked room.

How the community answered

(24 responses)
  • A
    21% (5)
  • B
    8% (2)
  • C
    13% (3)
  • D
    58% (14)

Why each option

With strong credentials already configured and wireless already disabled, the remaining vulnerability is physical access to the router sitting in an unsecured location. Placing the router in a locked room addresses this gap.

ADisable the router's remote management feature.

Disabling remote management is a valid hardening step, but physical security is more immediately critical given the router's openly accessible location under the front desk.

BEnable WPA2 wireless encryption.

WPA2 wireless encryption is irrelevant because the scenario states wireless is already disabled on the router.

CChange the router's default admin name and password.

The scenario explicitly states the router is already configured with strong device credentials, so changing default credentials has already been completed.

DPlace the router in a locked room.Correct

The scenario explicitly states the router already has strong device credentials and wireless is already disabled, so those common hardening steps are complete. The remaining security gap is physical - the router is accessible to anyone at or near the front desk, allowing direct physical tampering, console access, or factory reset attacks. Placing it in a locked room eliminates this physical attack surface, which is the logical next hardening step.

Concept tested: Physical security for network hardware in SOHO environments

Source: https://www.cisa.gov/news-events/news/securing-network-infrastructure-devices

Topics

#SOHO security#physical security#router security#network hardening

Community Discussion

No community discussion yet for this question.

Full 220-802 Practice