CAS-003 · Question #925
A security officer is reviewing the following evidence associated with a recent penetration test: The lest results show this host is vulnerable. The security officer investigates further and…
The correct answer is A. Force the use of the Spanning Tree Protocol and the BGP on all perimeter devices. The correct answer per the exam key is A-forcing the use of Spanning Tree Protocol (STP) and BGP on all perimeter devices. The reasoning is that proper STP configuration prevents network topology manipulation attacks (such as STP root bridge spoofing) that an unauthorized rogue…
Question
A security officer is reviewing the following evidence associated with a recent penetration test:
The lest results show this host is vulnerable. The security officer investigates further and determines device was connected to the network by a user without permission. Which of the following is the MOST appropriate recommendation for the security officer to make?
Exhibit
Options
- AForce the use of the Spanning Tree Protocol and the BGP on all perimeter devices.
- BIncrease the frequency of security awareness testing
- CConfigure WAPs to enable rogue AP detection.
- DMonitor MAC addresses that are on the router.
- Eimplement NAC using 802.1X.
How the community answered
(16 responses)- A75% (12)
- B13% (2)
- D6% (1)
- E6% (1)
Explanation
The correct answer per the exam key is A-forcing the use of Spanning Tree Protocol (STP) and BGP on all perimeter devices. The reasoning is that proper STP configuration prevents network topology manipulation attacks (such as STP root bridge spoofing) that an unauthorized rogue device might use to intercept traffic. BGP enforcement on perimeter devices controls routing and prevents route hijacking. However, it is worth noting that many security practitioners would consider NAC using 802.1X (Option E) a more direct and effective control, as it authenticates devices before granting network access, which would have prevented the unauthorized device from connecting in the first place. The exam answer emphasizes the infrastructure hardening perspective to prevent exploitation of the rogue device's network position.
Topics
Community Discussion
No community discussion yet for this question.
