nerdexam
CompTIA

PT0-002 · Question #205

An Nmap scan of a network switch reveals the following: Which of the following technical controls will most likely be the FIRST recommendation for this device?

The correct answer is B. System-hardening techniques. When Nmap reveals vulnerabilities on a network switch, the first recommendation should be to apply comprehensive system-hardening techniques.

Vulnerability discovery and analysis

Question

An Nmap scan of a network switch reveals the following:

Which of the following technical controls will most likely be the FIRST recommendation for this device?

Exhibit

PT0-002 question #205 exhibit

Options

  • AEncrypted passwords
  • BSystem-hardening techniques
  • CMultifactor authentication
  • DNetwork segmentation

How the community answered

(19 responses)
  • A
    16% (3)
  • B
    74% (14)
  • C
    5% (1)
  • D
    5% (1)

Why each option

When Nmap reveals vulnerabilities on a network switch, the first recommendation should be to apply comprehensive system-hardening techniques.

AEncrypted passwords

Encrypted passwords are a specific security control and one aspect of system hardening, but not as comprehensive as the overarching category of 'system-hardening techniques.'

BSystem-hardening techniquesCorrect

System-hardening techniques encompass a wide range of security configurations and practices, including disabling unnecessary services, changing default credentials, patching known vulnerabilities, and applying secure access controls. This comprehensive approach is the most fundamental 'first recommendation' to address multiple potential issues revealed by an Nmap scan on a network device.

CMultifactor authentication

Multifactor authentication is a strong access control, but it might not be supported by all network switches or be the most fundamental initial step before basic hardening measures are applied.

DNetwork segmentation

Network segmentation is a network architecture design principle, not a direct security control to be applied to a specific device to remediate its internal vulnerabilities found by an Nmap scan.

Concept tested: Network device security, system hardening

Source: https://nvlpubs.nist.gov/nistpubs/legacy/sp/nistspecialpublication800-70r2.pdf

Topics

#Vulnerability Scanning#Device Hardening#Network Security#Security Controls

Community Discussion

No community discussion yet for this question.

Full PT0-002 Practice