Courseiva
hardMultiple Select

200-201 Practice Question: A security policy mandates that all network…

A security policy mandates that all network devices must be hardened. Which THREE of the following are common hardening best practices for routers and switches? (Select three.)

⚠ Common exam trap

Cisco often tests the distinction between secure and insecure protocols, so the trap here is that candidates may mistakenly consider Telnet acceptable for remote management because it is widely used, ignoring that it lacks encryption and violates hardening standards.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement access control lists (ACLs)

Option A is correct because implementing access control lists (ACLs) on routers and switches restricts which traffic is permitted to reach the management plane and transit the device, enforcing least-privilege filtering as a core hardening control. Option B is correct because disabling unused services (for example, CDP, LLDP, HTTP server, or unused routing protocols) reduces the attack surface by eliminating unnecessary listening ports and daemons that could be exploited. Option E is correct because SNMPv3 with strong authentication (authNoPriv or authPriv using SHA and AES) replaces insecure SNMPv1/v2c community strings with encrypted, authenticated management traffic. Option C is not a hardening practice because Telnet transmits credentials and session data in cleartext; SSH should be used instead. Option D is not a hardening practice because default credentials are widely known and must be changed immediately during initial setup.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Implement access control lists (ACLs)

    Why this is correct

    ACLs filter traffic by source, destination, port and protocol, restricting management and transit access to only what each interface requires. This enforces least privilege on the device itself, directly satisfying the hardening mandate by preventing unauthorised reachability to routers and switches.

  • ✓

    Disable unused services

    Why this is correct

    Disabling unused services removes listening daemons such as Telnet, HTTP or CDP that attackers could exploit, shrinking the attack surface. This directly satisfies the hardening mandate by ensuring only required functions run on each router and switch.

  • ✗

    Enable Telnet for remote management

    Why it's wrong here

    Telnet transmits management credentials and sessions in cleartext, so anyone capturing traffic can read them, defeating the hardening mandate. It tempts because Telnet is simple and universally supported, but hardening requires SSH or an encrypted management channel instead.

  • ✗

    Use default credentials for initial setup

    Why it's wrong here

    Default credentials are publicly documented, so leaving them enabled lets anyone authenticate to the device, directly contradicting hardening. It tempts as a convenient starting point during initial provisioning, but hardening requires changing them immediately; the correct practice is disabling unused services and applying ACLs.

  • ✓

    Enable SNMPv3 with strong authentication

    Why this is correct

    SNMPv3 adds authentication and encryption, unlike v1 and v2c, which transmit community strings in cleartext. Enabling it with strong authentication satisfies the hardening mandate by preventing unauthorised read/write access to device management information, directly reducing the attack surface of routers and switches.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.