nerdexam
Cisco

400-007 · Question #283

An IT service provider is upgrading network infrastructure to comply with PCI security standards. The network team finds that 802.1X and VPN authentication based on locally-significant certificates…

The correct answer is A. Enable phone VPN authentication based on end-user username and password. When legacy phones cannot support certificate-based 802.1X or VPN authentication required by PCI standards, username and password VPN authentication serves as a compliant fallback mechanism.

Designing Security

Question

An IT service provider is upgrading network infrastructure to comply with PCI security standards. The network team finds that 802.1X and VPN authentication based on locally-significant certificates are not available on some legacy phones. Which workaround solution meets the requirement?

Options

  • AEnable phone VPN authentication based on end-user username and password
  • BReplace legacy phones with new phones because the legacy phones will lose trust if the
  • CTemporarily allow fallback to TLS 1.0 when using certificates and then upgrade the software on
  • DUse authentication-based clear text password with no EAP-MD5 on the legacy phones

How the community answered

(33 responses)
  • A
    73% (24)
  • B
    6% (2)
  • C
    15% (5)
  • D
    6% (2)

Why each option

When legacy phones cannot support certificate-based 802.1X or VPN authentication required by PCI standards, username and password VPN authentication serves as a compliant fallback mechanism.

AEnable phone VPN authentication based on end-user username and passwordCorrect

Username and password-based VPN authentication is a recognized alternative when device certificates are not supported by legacy hardware. It maintains an authenticated and encrypted tunnel to the network, satisfying PCI DSS requirements for protecting cardholder data in transit. This workaround avoids the need to replace hardware while still enforcing access control.

BReplace legacy phones with new phones because the legacy phones will lose trust if the

Replacing all legacy phones is a hardware procurement action, not a workaround solution, and does not address the immediate compliance requirement.

CTemporarily allow fallback to TLS 1.0 when using certificates and then upgrade the software on

Allowing fallback to TLS 1.0 violates PCI DSS requirements, as TLS 1.0 is explicitly prohibited under PCI DSS v3.2.1 and later due to known vulnerabilities such as POODLE.

DUse authentication-based clear text password with no EAP-MD5 on the legacy phones

Clear text password authentication provides no encryption and EAP-MD5 is considered cryptographically weak, both of which fail PCI security standards for network authentication.

Concept tested: Legacy device workarounds for PCI-compliant VPN authentication

Source: https://docs.cisco.com/en/cisco-secure-access-control/index.html

Topics

#802.1X#VPN authentication#legacy devices#PCI compliance

Community Discussion

No community discussion yet for this question.

Full 400-007 Practice