A security policy mandates that all network devices must be hardened. Which THREE of the following are common hardening best practices for routers and switches? (Select three.)
ACLs filter traffic by source, destination, port and protocol, restricting management and transit access to only what each interface requires. This enforces least privilege on the device itself, directly satisfying the hardening mandate by preventing unauthorised reachability to routers and switches.
Why this answer
Option A is correct because implementing access control lists (ACLs) on routers and switches restricts which traffic is permitted to reach the management plane and transit the device, enforcing least-privilege filtering as a core hardening control. Option B is correct because disabling unused services (for example, CDP, LLDP, HTTP server, or unused routing protocols) reduces the attack surface by eliminating unnecessary listening ports and daemons that could be exploited. Option E is correct because SNMPv3 with strong authentication (authNoPriv or authPriv using SHA and AES) replaces insecure SNMPv1/v2c community strings with encrypted, authenticated management traffic.
Option C is not a hardening practice because Telnet transmits credentials and session data in cleartext; SSH should be used instead. Option D is not a hardening practice because default credentials are widely known and must be changed immediately during initial setup.
Exam trap
Cisco often tests the distinction between secure and insecure protocols, so the trap here is that candidates may mistakenly consider Telnet acceptable for remote management because it is widely used, ignoring that it lacks encryption and violates hardening standards.