SSCP Network and Communications Security Practice Question
A security administrator is hardening a data center switch. Management requires that only the switch's configured management station can initiate a remote CLI session, and that the switch never accept an inbound management connection from any other host. Which control should the administrator implement on the switch to meet this requirement?
⚠ Common exam trap
The trap here is assuming that strong authentication alone limits who can connect to a device, when reachability filtering must be applied separately to restrict session sources.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
An inbound access control list applied to the management VLAN interface that permits only the management station's IP address to reach TCP port 22
Restricting the management plane by source address is the only control listed that limits who may initiate an administrative session. An inbound ACL bound to the management interface permits the approved management station and denies everything else, directly matching the stated policy. Authentication, port security, and loop-prevention features address different problems and leave the management service reachable from any host on the network.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
An inbound access control list applied to the management VLAN interface that permits only the management station's IP address to reach TCP port 22
Why this is correct
Filtering inbound traffic to the management VLAN so that only the designated management host can reach the SSH service enforces exactly the stated requirement: the switch accepts remote CLI sessions only when they originate from the approved station. All other source addresses are dropped before they can reach the management plane, which also reduces the attack surface of the device itself.
- ✗
BPDU Guard enabled on all access ports to prevent rogue spanning-tree devices
Why it's wrong here
BPDU Guard err-disables a port when it receives spanning-tree BPDUs, protecting the topology from unauthorized switches. It is a Layer 2 loop-prevention feature and has no bearing on which IP address may initiate an SSH session to the management interface. It cannot restrict management-plane access, so it fails the scenario.
- ✗
Port security configured on every access port with a maximum of one learned MAC address
Why it's wrong here
Port security limits which source MAC addresses may appear on a switchport, which prevents MAC flooding and unauthorized devices on access ports. It does nothing to restrict which IP host may open an SSH session to the switch's own management interface, so a host on an already-authorized port could still reach the CLI. It does not satisfy the requirement.
- ✗
A TACACS+ or RADIUS server that authenticates all administrative logins with individual accounts
Why it's wrong here
Centralized AAA authentication is valuable because it provides accountability and per-user credentials, but it only verifies who is connecting. It still allows any reachable host to attempt a session, so an attacker on the network can brute-force or exploit the management service. The requirement is about which sources may connect, not about proving identity after connection.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.