Courseiva
hardMultiple SelectObjective-mapped

200-201 Practice Question: A security policy mandates that all network…

A security policy mandates that all network devices must be hardened. Which THREE of the following are common hardening best practices for routers and switches? (Select three.)

⚠ Common exam trap

Cisco often tests the distinction between secure and insecure protocols, so the trap here is that candidates may mistakenly consider Telnet acceptable for remote management because it is widely used, ignoring that it lacks encryption and violates hardening standards.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Implement access control lists (ACLs)

Implementing access control lists (ACLs) on routers and switches is a fundamental hardening practice because ACLs filter traffic based on source/destination IP addresses, ports, and protocols, thereby restricting unauthorized access and mitigating threats like spoofing or reconnaissance. By default, Cisco devices permit all traffic unless explicitly denied, so ACLs enforce the principle of least privilege at the network layer.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Implement access control lists (ACLs)

    Why this is correct

    ACLs restrict traffic to only necessary communications.

  • Disable unused services

    Why this is correct

    Reduces attack surface by eliminating unnecessary services.

  • Enable Telnet for remote management

    Why it's wrong here

    Telnet sends data in plaintext; SSH should be used instead.

  • Use default credentials for initial setup

    Why it's wrong here

    Default credentials are well-known and should be changed immediately.

  • Enable SNMPv3 with strong authentication

    Why this is correct

    SNMPv3 provides encryption and authentication, unlike earlier versions.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

One of 979 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.