nerdexam
CompTIA

220-802 · Question #950

A technician is hardening the security on a wired SOHO router and needs the router to still be able to connect to the Internet. Which of the following methods would the technician do to achieve this?

The correct answer is C. Disable unused ports. Disabling unused ports (physical LAN ports or logical service ports) reduces the attack surface by preventing connections through ports that serve no legitimate purpose, while leaving the WAN port active so Internet connectivity is maintained. Disabling NAT would break Internet…

Networking

Question

A technician is hardening the security on a wired SOHO router and needs the router to still be able to connect to the Internet. Which of the following methods would the technician do to achieve this?

Options

  • ADisable NAT
  • BDisable the SSID broadcast
  • CDisable unused ports
  • DEnable WPA2

How the community answered

(61 responses)
  • A
    5% (3)
  • B
    10% (6)
  • C
    82% (50)
  • D
    3% (2)

Explanation

Disabling unused ports (physical LAN ports or logical service ports) reduces the attack surface by preventing connections through ports that serve no legitimate purpose, while leaving the WAN port active so Internet connectivity is maintained. Disabling NAT would break Internet access for all LAN devices since NAT translates private IPs to the public IP. Disabling SSID broadcast and enabling WPA2 are both wireless security measures and irrelevant on a wired-only context. Disabling unused ports is the one action that hardens the router without disrupting Internet access.

Topics

#SOHO router#network hardening#port security#security best practices

Community Discussion

No community discussion yet for this question.

Full 220-802 Practice