PT0-002 · Question #205
An Nmap scan of a network switch reveals the following: Which of the following technical controls will most likely be the FIRST recommendation for this device?
The correct answer is B. System-hardening techniques. When Nmap reveals vulnerabilities on a network switch, the first recommendation should be to apply comprehensive system-hardening techniques.
Question
An Nmap scan of a network switch reveals the following:
Which of the following technical controls will most likely be the FIRST recommendation for this device?
Exhibit
Options
- AEncrypted passwords
- BSystem-hardening techniques
- CMultifactor authentication
- DNetwork segmentation
How the community answered
(19 responses)- A16% (3)
- B74% (14)
- C5% (1)
- D5% (1)
Why each option
When Nmap reveals vulnerabilities on a network switch, the first recommendation should be to apply comprehensive system-hardening techniques.
Encrypted passwords are a specific security control and one aspect of system hardening, but not as comprehensive as the overarching category of 'system-hardening techniques.'
System-hardening techniques encompass a wide range of security configurations and practices, including disabling unnecessary services, changing default credentials, patching known vulnerabilities, and applying secure access controls. This comprehensive approach is the most fundamental 'first recommendation' to address multiple potential issues revealed by an Nmap scan on a network device.
Multifactor authentication is a strong access control, but it might not be supported by all network switches or be the most fundamental initial step before basic hardening measures are applied.
Network segmentation is a network architecture design principle, not a direct security control to be applied to a specific device to remediate its internal vulnerabilities found by an Nmap scan.
Concept tested: Network device security, system hardening
Source: https://nvlpubs.nist.gov/nistpubs/legacy/sp/nistspecialpublication800-70r2.pdf
Topics
Community Discussion
No community discussion yet for this question.
