220-802 · Question #950
A technician is hardening the security on a wired SOHO router and needs the router to still be able to connect to the Internet. Which of the following methods would the technician do to achieve this?
The correct answer is C. Disable unused ports. Disabling unused ports (physical LAN ports or logical service ports) reduces the attack surface by preventing connections through ports that serve no legitimate purpose, while leaving the WAN port active so Internet connectivity is maintained. Disabling NAT would break Internet…
Question
A technician is hardening the security on a wired SOHO router and needs the router to still be able to connect to the Internet. Which of the following methods would the technician do to achieve this?
Options
- ADisable NAT
- BDisable the SSID broadcast
- CDisable unused ports
- DEnable WPA2
How the community answered
(61 responses)- A5% (3)
- B10% (6)
- C82% (50)
- D3% (2)
Explanation
Disabling unused ports (physical LAN ports or logical service ports) reduces the attack surface by preventing connections through ports that serve no legitimate purpose, while leaving the WAN port active so Internet connectivity is maintained. Disabling NAT would break Internet access for all LAN devices since NAT translates private IPs to the public IP. Disabling SSID broadcast and enabling WPA2 are both wireless security measures and irrelevant on a wired-only context. Disabling unused ports is the one action that hardens the router without disrupting Internet access.
Topics
Community Discussion
No community discussion yet for this question.