220-802 · Question #548
An administrator sets up a wireless device that they will need to manage across the Internet. Which of the following security measures would BEST prevent unauthorized access to the device from the…
The correct answer is B. Change the default username and password. Changing the default username and password on a remotely managed wireless device is the most critical step to prevent unauthorized access, since default credentials are publicly documented and trivially exploited.
Question
An administrator sets up a wireless device that they will need to manage across the Internet. Which of the following security measures would BEST prevent unauthorized access to the device from the Internet?
Options
- ASet the channels to wireless 802.11n only
- BChange the default username and password
- CEnable the wireless AP's MAC filtering
- DEnable the wireless AP's WPA2 security
How the community answered
(18 responses)- A6% (1)
- B72% (13)
- C6% (1)
- D17% (3)
Why each option
Changing the default username and password on a remotely managed wireless device is the most critical step to prevent unauthorized access, since default credentials are publicly documented and trivially exploited.
Setting the wireless channel to 802.11n only affects the radio protocol used by wireless clients and has no effect on Internet-facing management access security.
Most wireless routers and APs ship with well-known default credentials (e.g., admin/admin or admin/password) that are published in vendor manuals and online databases. An attacker accessing the management interface from the Internet only needs these defaults to gain full control. Changing the credentials to a strong, unique combination eliminates this publicly known attack vector and is the foundational security step for any internet-facing device.
MAC filtering applies only to wireless client associations on the local network and does not protect the device's management interface when accessed over the Internet.
WPA2 secures the over-the-air wireless connection between clients and the AP, but it does not protect the device's web-based management interface from Internet-based attacks.
Concept tested: Changing default credentials on network devices
Source: https://www.cisa.gov/news-events/alerts/2018/09/13/hidden-cobra-north-koreas-continued-use-malicious-cyber-activity
Topics
Community Discussion
No community discussion yet for this question.