350-401 Security Practice Question
A network security team is hardening a Cisco IOS-XE router that terminates a site-to-site VPN to the internet. They want to ensure that the router itself cannot be managed from untrusted networks and that its management protocols are protected. Which two configuration actions achieve these goals? (Choose two.)
⚠ Common exam trap
The trap here is treating convenience measures such as disabling exec-timeout, enabling plain HTTP, or creating passwordless privileged accounts as acceptable hardening, when they actually increase exposure on an internet-facing router.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Apply an access list to the VTY lines that permits only trusted management subnets and add the transport input ssh command
Hardening the management plane requires restricting who can reach the management interfaces and how. Limiting VTY access with an ACL to trusted subnets and forcing SSH eliminates cleartext and unauthorized remote logins, while an interface ACL that blocks SNMP and NETCONF from untrusted sources prevents those services from being exploited from the internet. Together these actions protect the router's management plane without disrupting the site-to-site VPN traffic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable the exec-timeout 0 0 command on all VTY lines to prevent session lockouts during maintenance
Why it's wrong here
Setting exec-timeout to 0 0 disables idle timeouts, leaving administrative sessions open indefinitely and increasing exposure if a terminal is left unattended. This weakens security rather than hardening it, and contradicts the goal of protecting management access on an internet-facing router. Idle timeouts should be short, not disabled.
- ✓
Apply an access list to the VTY lines that permits only trusted management subnets and add the transport input ssh command
Why this is correct
Restricting VTY access with an ACL to trusted management subnets and disabling Telnet via transport input ssh prevents unauthenticated or cleartext management from untrusted networks. This directly addresses the goal of protecting the router's management plane from the internet and is a standard hardening step on Cisco IOS-XE edge devices.
- ✗
Configure a local username with privilege level 15 and no password to ensure emergency access is always available
Why it's wrong here
A privilege-15 account without a password is a severe security weakness that allows anyone reaching the login prompt to obtain full control. It directly undermines the goal of protecting the router from untrusted networks. Emergency access should be handled with securely stored credentials, AAA, and out-of-band management, not with passwordless privileged accounts.
- ✗
Enable the ip http server command to allow web-based management as a backup access method
Why it's wrong here
Enabling the plain HTTP server exposes an unencrypted management interface and broadens the attack surface, which is the opposite of hardening. Management should use HTTPS with strong authentication if web access is needed at all, and only from trusted networks. This action does not protect the router and should be avoided on an internet-facing device.
- ✓
Configure an ACL on the WAN interface that denies SNMP and NETCONF from untrusted sources while permitting VPN traffic
Why this is correct
An interface ACL that blocks SNMP and NETCONF from untrusted sources prevents these management protocols from being reached from the internet while allowing the site-to-site VPN traffic to pass. This protects management services at the data plane edge and complements VTY hardening, satisfying the stated requirement to protect the router from untrusted management access.
Visual reference
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
Learn chapter
IP Services: DHCP, NAT, and DNS
Key term
IPsec Tunnel
An IPsec tunnel is a secure, encrypted connection between two network devices that protects data as it travels across the internet or another untrusted network.
Key term
NETCONF Protocol
NETCONF is a network management protocol that uses a structured data format to configure, retrieve, and modify network devices in a standard, programmatic way.
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.