CERTIVIEW

Friday, 8 January 2016

CCNP Security Question of the Week: Harden a Switch

ccnpQoW01

Which three commands can be used to harden a switch? (Choose three.)

A. switch(config)# spanning-tree bpdufilter default
B. switch(config)# ip dhcp snooping
C. switch(config)# errdisable recovery interval 900
D. switch(config-if)# spanning-tree guard root
E. switch(config-if)# spanning-tree bpduguard disable
F. switch(config-if)# no cdp enable
G. switch(config)# service harden

Reveal Answer

Answer: B, D and F.

Even though it would be nice to have the “service harden” command to secure the switch, there is no such command.  The recommendation from Cisco is based on a white paper from the NSA is to enable DHCP snooping to block any rogue DHCP server: Spanning Tree Root Guard to block others from taking over the spanning tree topology; and to disable Cisco Discovery Protocol so the device stop advertising itself to whomever that may be listening.  There are other features that could be enabled or disabled, but those are not on this list.

 

Related Resources
Cisco White Papers

Related Course
CCNP Security e-Camp

CCNP Security Question of the Week Series

  • CCNP Security Question of the Week: Cisco ASA Security Context
  • CCNP Security Question of the Week: Authenticating ASDM Users
  • CCNP Security Question of the Week: Layer 5-7 Policy Maps
  • CCNP Security Question of the Week: 802.1X
  • CCNP Security Question of the Week: IPS Updates
  • CCNP Security Question of the Week: IPsec VPN Tunnels
  • CCNP Security Question of the Week: AnyConnect VPN Client
  • CCNP Security Question of the Week: ASA AIP-SSM and ASA AIP-SSC
  • CCNP Security Question of the Week: Disable DHCP Server Service
  • CCNP Security Question of the Week: Cisco ASA Security Appliance Access List
  • CCNP Security Question of the Week: Network Address Translation
  • CCNP Security Question of the Week: Harden a Switch
  • CCNP Security Question of the Week: SSH Login
  • CCNP Security Question of the Week: Packet-Tracer Command
  • CCNP Security Question of the Week: SSL Ciphers
  • CCNP Security Question of the Week: VLAN Hopping
  • CCNP Security Question of the Week: DHCP Server Service
  • CCNP Security Question of the Week: Default Behavior of an Access List
  • CCNP Security Question of the Week: NAT Control on Cisco ASA Version 8.3
  • CCNP Security Question of the Week: IPS Anomaly Detection Features
  • CCNP Security Question of the Week: Bogus IPv6 Addresses
  • CCNP Security Question of the Week: Harden a Switch


from
CERTIVIEW
Unknown at 04:04
Share

No comments:

Post a Comment

‹
›
Home
View web version

About Me

Unknown
View my complete profile
Powered by Blogger.