SY0-501 · Question #220
Which of the following precautions MINIMIZES the risk from network attacks directed at multifunction printers, as well as the impact on functionality at the same time?
The correct answer is A. Isolating the systems using VLANs. Isolating multifunction printers using VLANs is the most effective precaution to minimize the risk of network attacks and limit their impact, while simultaneously ensuring the printers' functionality remains intact.
Question
Which of the following precautions MINIMIZES the risk from network attacks directed at multifunction printers, as well as the impact on functionality at the same time?
Options
- AIsolating the systems using VLANs
- BInstalling a software-based IPS on all devices
- CEnabling full disk encryption
- DImplementing a unique user PIN access functions
How the community answered
(40 responses)- A73% (29)
- B15% (6)
- C5% (2)
- D8% (3)
Why each option
Isolating multifunction printers using VLANs is the most effective precaution to minimize the risk of network attacks and limit their impact, while simultaneously ensuring the printers' functionality remains intact.
VLANs logically segment the network, allowing multifunction printers to be placed on a dedicated isolated segment, which significantly reduces their exposure to the broader network and limits the potential for lateral movement by attackers if a printer is compromised, all without hindering their core operational functions.
Multifunction printers typically have limited processing capabilities and specialized embedded operating systems that make it impractical or impossible to install and effectively run a software-based IPS, which would also severely degrade their performance.
Full disk encryption protects data at rest on the printer's internal storage from unauthorized physical access but does not prevent or mitigate active network-based attacks targeting the printer's services or vulnerabilities.
Implementing unique user PIN access controls physical access to the printer's functions (e.g., releasing print jobs) and does not address or minimize network-based attack vectors or vulnerabilities.
Concept tested: Network segmentation and isolation using VLANs for security
Source: https://www.cisco.com/c/en/us/td/docs/solutions/Enterprise/Campus/campbest/design_guide_chap6.html
Topics
Community Discussion
No community discussion yet for this question.