Courseiva

SSCP Network and Communications Security Practice Question

A security administrator is hardening a data center switch. Management requires that only the switch's configured management station can initiate a remote CLI session, and that the switch never accept an inbound management connection from any other host. Which control should the administrator implement on the switch to meet this requirement?

⚠ Common exam trap

The trap here is assuming that strong authentication alone limits who can connect to a device, when reachability filtering must be applied separately to restrict session sources.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

An inbound access control list applied to the management VLAN interface that permits only the management station's IP address to reach TCP port 22

Restricting the management plane by source address is the only control listed that limits who may initiate an administrative session. An inbound ACL bound to the management interface permits the approved management station and denies everything else, directly matching the stated policy. Authentication, port security, and loop-prevention features address different problems and leave the management service reachable from any host on the network.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    An inbound access control list applied to the management VLAN interface that permits only the management station's IP address to reach TCP port 22

    Why this is correct

    Filtering inbound traffic to the management VLAN so that only the designated management host can reach the SSH service enforces exactly the stated requirement: the switch accepts remote CLI sessions only when they originate from the approved station. All other source addresses are dropped before they can reach the management plane, which also reduces the attack surface of the device itself.

  • ✗

    BPDU Guard enabled on all access ports to prevent rogue spanning-tree devices

    Why it's wrong here

    BPDU Guard err-disables a port when it receives spanning-tree BPDUs, protecting the topology from unauthorized switches. It is a Layer 2 loop-prevention feature and has no bearing on which IP address may initiate an SSH session to the management interface. It cannot restrict management-plane access, so it fails the scenario.

  • ✗

    Port security configured on every access port with a maximum of one learned MAC address

    Why it's wrong here

    Port security limits which source MAC addresses may appear on a switchport, which prevents MAC flooding and unauthorized devices on access ports. It does nothing to restrict which IP host may open an SSH session to the switch's own management interface, so a host on an already-authorized port could still reach the CLI. It does not satisfy the requirement.

  • ✗

    A TACACS+ or RADIUS server that authenticates all administrative logins with individual accounts

    Why it's wrong here

    Centralized AAA authentication is valuable because it provides accountability and per-user credentials, but it only verifies who is connecting. It still allows any reachable host to attempt a session, so an attacker on the network can brute-force or exploit the management service. The requirement is about which sources may connect, not about proving identity after connection.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.