CERTIVIEW

Friday, 26 February 2016

CCNP Security Question of the Week: Prevent VLAN Hopping

ccnpQoW01

According to Cisco best practices, which two commands help prevent VLAN hopping? (Choose two.)

A. switchport mode access
B. switchport access vlan 2
C. switchport mode trunk
D. switchport access vlan 1
E. switchport trunk native vlan 1
F. switchport protected

Reveal Answer

Answer: A and B.

The idea is simply enough, change the default behavior of being dynamic desirable or dynamic auto, to making the port an access port.  That way, if whatever device is attached to the port, it will not be able to use 802.1Q tagging to hop from one VLAN to another.  Also, as an access port, the default VLAN is VLAN 1, so move it to another, unused VLAN number to black hole any traffic from any unauthorized devices that might connect to the switch.

 

Related Resources
Cisco White Papers

Related Course
CCNP Security e-Camp

CCNP Security Question of the Week Series

  • CCNP Security Question of the Week: Cisco ASA Security Context
  • CCNP Security Question of the Week: Authenticating ASDM Users
  • CCNP Security Question of the Week: Layer 5-7 Policy Maps
  • CCNP Security Question of the Week: 802.1X
  • CCNP Security Question of the Week: IPS Updates
  • CCNP Security Question of the Week: IPsec VPN Tunnels
  • CCNP Security Question of the Week: AnyConnect VPN Client
  • CCNP Security Question of the Week: ASA AIP-SSM and ASA AIP-SSC
  • CCNP Security Question of the Week: Disable DHCP Server Service
  • CCNP Security Question of the Week: Cisco ASA Security Appliance Access List
  • CCNP Security Question of the Week: Network Address Translation
  • CCNP Security Question of the Week: Harden a Switch
  • CCNP Security Question of the Week: SSH Login
  • CCNP Security Question of the Week: Packet-Tracer Command
  • CCNP Security Question of the Week: SSL Ciphers
  • CCNP Security Question of the Week: VLAN Hopping
  • CCNP Security Question of the Week: DHCP Server Service
  • CCNP Security Question of the Week: Default Behavior of an Access List
  • CCNP Security Question of the Week: NAT Control on Cisco ASA Version 8.3
  • CCNP Security Question of the Week: IPS Anomaly Detection Features
  • CCNP Security Question of the Week: Bogus IPv6 Addresses
  • CCNP Security Question of the Week: Harden a Switch
  • CCNP Security Question of the Week: SSH Login
  • CCNP Security Question of the Week: NTP on a Cisco ASA Default Settings
  • CCNP Security Question of the Week: Packet-tracer Command
  • CCNP Security Question of the Week: SSL Ciphers
  • CCNP Security Question of the Week: Prevent VLAN Hopping


from
CERTIVIEW
Unknown at 03:31
Share

No comments:

Post a Comment

‹
›
Home
View web version

About Me

Unknown
View my complete profile
Powered by Blogger.