nerdexam
HP

HPE6-A84 · Question #40

Refer to the scenario. A customer has asked you to review their AOS-CX switches for potential vulnerabilities. The configuration for these switches is shown below: What is one immediate remediation…

The correct answer is D. Disabling Telnet. According to the AOS-CX Switches Multiple Vulnerabilities1, one of the vulnerabilities (CVE- 2021-41001) affects the Telnet service on AOS-CX switches. This vulnerability allows an unauthenticated remote attacker to cause a denial-of-service condition on the switch by sending…

Troubleshooting Advanced Network Security

Question

Refer to the scenario. A customer has asked you to review their AOS-CX switches for potential vulnerabilities. The configuration for these switches is shown below:

What is one immediate remediation that you should recommend?

Options

  • AChanging the switch's DNS server to the mgmt VRF
  • BSetting the clock manually instead of using NTP
  • CEither disabling DHCPv4-snoopinq or leaving it enabled, but also enabling ARP inspection
  • DDisabling Telnet

How the community answered

(23 responses)
  • A
    4% (1)
  • C
    4% (1)
  • D
    91% (21)

Explanation

According to the AOS-CX Switches Multiple Vulnerabilities1, one of the vulnerabilities (CVE- 2021-41001) affects the Telnet service on AOS-CX switches. This vulnerability allows an unauthenticated remote attacker to cause a denial-of-service condition on the switch by sending specially crafted Telnet packets. The impact of this vulnerability is high, as it could result in a loss of management access and network disruption. Therefore, one immediate remediation that you should recommend is to disable Telnet on the switch. This way, the switch can prevent any malicious Telnet traffic from reaching it and avoid the exploitation of this vulnerability.

Topics

#Telnet#AOS-CX#switch hardening#insecure protocols

Community Discussion

No community discussion yet for this question.

Full HPE6-A84 Practice