nerdexam
Cisco

350-201 · Question #9

Refer to the exhibit. An engineer received a report that an attacker has compromised a workstation and gained access to sensitive customer data from the network using insecure protocols. Which…

The correct answer is A. Use VLANs to segregate zones and the firewall to allow only required services and secured. Combining VLAN-based network segmentation with firewall rules that permit only required, encrypted services directly removes both the lateral movement path and the insecure protocol vector the attacker exploited.

Security Policies and Procedures

Question

Refer to the exhibit. An engineer received a report that an attacker has compromised a workstation and gained access to sensitive customer data from the network using insecure protocols. Which action prevents this type of attack in the future?

Exhibit

350-201 question #9 exhibit

Options

  • AUse VLANs to segregate zones and the firewall to allow only required services and secured
  • BDeploy a SOAR solution and correlate log alerts from customer zones
  • CDeploy IDS within sensitive areas and continuously update signatures
  • DUse syslog to gather data from multiple sources and detect intrusion logs for timely responses

How the community answered

(50 responses)
  • A
    78% (39)
  • B
    6% (3)
  • C
    4% (2)
  • D
    12% (6)

Why each option

Combining VLAN-based network segmentation with firewall rules that permit only required, encrypted services directly removes both the lateral movement path and the insecure protocol vector the attacker exploited.

AUse VLANs to segregate zones and the firewall to allow only required services and securedCorrect

VLANs isolate the sensitive customer data zone from general workstation segments, ensuring that a compromised workstation has no direct Layer 2 or Layer 3 path to sensitive resources without passing through an enforced security boundary. Firewall policies configured to allow only required services and secured protocols block insecure protocols such as Telnet, FTP, and HTTP that the attacker used to exfiltrate data. This combination addresses both the network access vector and the insecure protocol weakness simultaneously, preventing the same class of attack in the future.

BDeploy a SOAR solution and correlate log alerts from customer zones

SOAR improves detection and automated response speed but provides no enforcement mechanism to block insecure protocols or prevent lateral movement between network zones.

CDeploy IDS within sensitive areas and continuously update signatures

IDS sensors detect and alert on malicious traffic patterns but cannot enforce segmentation or block insecure protocol sessions, leaving the underlying attack vector open.

DUse syslog to gather data from multiple sources and detect intrusion logs for timely responses

Syslog aggregation supports log analysis and post-incident investigation but offers no preventive control over network access paths or the use of insecure protocols.

Concept tested: Network segmentation with VLANs and firewall policy to block insecure protocols

Source: https://www.cisco.com/c/en/us/td/docs/solutions/Enterprise/Security/SAFE_RG/SAFE_rg.html

Topics

#network segmentation#VLAN#insecure protocols#firewall policy

Community Discussion

No community discussion yet for this question.

Full 350-201 Practice