hardMultiple Select
200-201 Practice Question: A security policy mandates that all network…
A security policy mandates that all network devices must be hardened. Which THREE of the following are common hardening best practices for routers and switches? (Select three.)
⚠ Common exam trap
Cisco often tests the distinction between secure and insecure protocols, so the trap here is that candidates may mistakenly consider Telnet acceptable for remote management because it is widely used, ignoring that it lacks encryption and violates hardening standards.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement access control lists (ACLs)
Option A is correct because implementing access control lists (ACLs) on routers and switches restricts which traffic is permitted to reach the management plane and transit the device, enforcing least-privilege filtering as a core hardening control. Option B is correct because disabling unused services (for example, CDP, LLDP, HTTP server, or unused routing protocols) reduces the attack surface by eliminating unnecessary listening ports and daemons that could be exploited. Option E is correct because SNMPv3 with strong authentication (authNoPriv or authPriv using SHA and AES) replaces insecure SNMPv1/v2c community strings with encrypted, authenticated management traffic. Option C is not a hardening practice because Telnet transmits credentials and session data in cleartext; SSH should be used instead. Option D is not a hardening practice because default credentials are widely known and must be changed immediately during initial setup.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Implement access control lists (ACLs)
Why this is correct
ACLs filter traffic by source, destination, port and protocol, restricting management and transit access to only what each interface requires. This enforces least privilege on the device itself, directly satisfying the hardening mandate by preventing unauthorised reachability to routers and switches.
- ✓
Disable unused services
Why this is correct
Disabling unused services removes listening daemons such as Telnet, HTTP or CDP that attackers could exploit, shrinking the attack surface. This directly satisfies the hardening mandate by ensuring only required functions run on each router and switch.
- ✗
Enable Telnet for remote management
Why it's wrong here
Telnet transmits management credentials and sessions in cleartext, so anyone capturing traffic can read them, defeating the hardening mandate. It tempts because Telnet is simple and universally supported, but hardening requires SSH or an encrypted management channel instead.
- ✗
Use default credentials for initial setup
Why it's wrong here
Default credentials are publicly documented, so leaving them enabled lets anyone authenticate to the device, directly contradicting hardening. It tempts as a convenient starting point during initial provisioning, but hardening requires changing them immediately; the correct practice is disabling unused services and applying ACLs.
- ✓
Enable SNMPv3 with strong authentication
Why this is correct
SNMPv3 adds authentication and encryption, unlike v1 and v2c, which transmit community strings in cleartext. Enabling it with strong authentication satisfies the hardening mandate by preventing unauthorised read/write access to device management information, directly reducing the attack surface of routers and switches.
Visual reference
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.