Courseiva
mediumMultiple SelectObjective-mapped

350-701 Practice Question: Which TWO of the following are best practices for…

Which TWO of the following are best practices for securing Cisco routers against unauthorized access? (Choose two.)

⚠ Common exam trap

Cisco often tests the distinction between 'service password-encryption' (type 7) and the stronger 'enable secret' (MD5 hash), leading candidates to mistakenly think type 7 encryption is secure.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Disable unused services like HTTP server and CDP

C is correct because disabling unused services like HTTP server and CDP reduces the attack surface of the router. The HTTP server can be exploited for web-based attacks, and CDP can leak sensitive network topology information. Cisco best practices recommend disabling all unnecessary services to minimize exposure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Enable SNMP read-write community string for monitoring

    Why it's wrong here

    SNMP read-write is a security risk; use read-only or SNMPv3.

  • Use the 'service password-enforcement' command to encrypt passwords with type 7

    Why it's wrong here

    Type 7 encryption is reversible; use type 8 or 9 for stronger security.

  • Disable unused services like HTTP server and CDP

    Why this is correct

    Disabling unnecessary services reduces the attack surface.

  • Configure authentication using HTTP with local username/password

    Why it's wrong here

    HTTP is unencrypted; use HTTPS or SSH.

  • Use SSH version 2 for remote access

    Why this is correct

    SSHv2 provides encrypted remote administration.

About these practice questions

This 350-701 question is part of Courseiva's 978-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-701 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-701 exam.