Courseiva
Security →hardMultiple Select

350-401 Security Practice Question

A network security team is hardening a Cisco IOS-XE router that terminates a site-to-site VPN to the internet. They want to ensure that the router itself cannot be managed from untrusted networks and that its management protocols are protected. Which two configuration actions achieve these goals? (Choose two.)

⚠ Common exam trap

The trap here is treating convenience measures such as disabling exec-timeout, enabling plain HTTP, or creating passwordless privileged accounts as acceptable hardening, when they actually increase exposure on an internet-facing router.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Apply an access list to the VTY lines that permits only trusted management subnets and add the transport input ssh command

Hardening the management plane requires restricting who can reach the management interfaces and how. Limiting VTY access with an ACL to trusted subnets and forcing SSH eliminates cleartext and unauthorized remote logins, while an interface ACL that blocks SNMP and NETCONF from untrusted sources prevents those services from being exploited from the internet. Together these actions protect the router's management plane without disrupting the site-to-site VPN traffic.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable the exec-timeout 0 0 command on all VTY lines to prevent session lockouts during maintenance

    Why it's wrong here

    Setting exec-timeout to 0 0 disables idle timeouts, leaving administrative sessions open indefinitely and increasing exposure if a terminal is left unattended. This weakens security rather than hardening it, and contradicts the goal of protecting management access on an internet-facing router. Idle timeouts should be short, not disabled.

  • ✓

    Apply an access list to the VTY lines that permits only trusted management subnets and add the transport input ssh command

    Why this is correct

    Restricting VTY access with an ACL to trusted management subnets and disabling Telnet via transport input ssh prevents unauthenticated or cleartext management from untrusted networks. This directly addresses the goal of protecting the router's management plane from the internet and is a standard hardening step on Cisco IOS-XE edge devices.

  • ✗

    Configure a local username with privilege level 15 and no password to ensure emergency access is always available

    Why it's wrong here

    A privilege-15 account without a password is a severe security weakness that allows anyone reaching the login prompt to obtain full control. It directly undermines the goal of protecting the router from untrusted networks. Emergency access should be handled with securely stored credentials, AAA, and out-of-band management, not with passwordless privileged accounts.

  • ✗

    Enable the ip http server command to allow web-based management as a backup access method

    Why it's wrong here

    Enabling the plain HTTP server exposes an unencrypted management interface and broadens the attack surface, which is the opposite of hardening. Management should use HTTPS with strong authentication if web access is needed at all, and only from trusted networks. This action does not protect the router and should be avoided on an internet-facing device.

  • ✓

    Configure an ACL on the WAN interface that denies SNMP and NETCONF from untrusted sources while permitting VPN traffic

    Why this is correct

    An interface ACL that blocks SNMP and NETCONF from untrusted sources prevents these management protocols from being reached from the internet while allowing the site-to-site VPN traffic to pass. This protects management services at the data plane edge and complements VTY hardening, satisfying the stated requirement to protect the router from untrusted management access.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

Quick reference

VPN Protocol Comparison

ProtocolPortEncryptionAuthenticationUse Case
IKEv2 / IPsecUDP 500 / 4500AES-256Certificates / PSKSite-to-site & remote access
SSL / TLS VPNTCP 443TLS 1.3Certificates / MFAClientless remote access
L2TP / IPsecUDP 1701AES (IPsec)PSK / CertificatesLegacy remote access
WireGuardUDP 51820ChaCha20Public keysModern high-performance VPN
PPTPTCP 1723MPPE (weak)MS-CHAPv2Legacy — avoid in production

PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.