Courseiva

SSCP Systems and Application Security Practice Question

During a security assessment, you discover that a Windows server has the Telnet service running. Which of the following is the BEST action to harden the server against this finding?

⚠ Common exam trap

SSCP often tests the misconception that restricting or monitoring Telnet makes it secure, when the fundamental flaw is lack of encryption, so replacement with SSH is the only proper hardening.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Remove the Telnet service and use SSH instead

The best action is to remove Telnet and use SSH instead because Telnet transmits data, including credentials, in cleartext, making it inherently insecure. SSH provides encrypted communication, eliminating the vulnerability. Removing the service also reduces the attack surface.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure a host-based firewall to allow Telnet only from specific IPs

    Why it's wrong here

    Allowing Telnet from specific IPs still transmits credentials and session data in cleartext, so the vulnerability remains. Firewall scoping suits restricting a service that must stay enabled for a trusted management subnet, not removing an insecure legacy protocol.

  • ✗

    Enable encryption on Telnet

    Why it's wrong here

    Telnet has no native encryption mechanism; TLS wrapping requires a different service such as SSH. Enabling encryption suits protocols designed with a cryptographic layer, whereas Telnet should simply be disabled and replaced with SSH for remote administration.

  • ✓

    Remove the Telnet service and use SSH instead

    Why this is correct

    Telnet transmits credentials and session data in cleartext, so any network observer can capture them. Removing the service eliminates that exposure, while SSH provides encrypted, authenticated remote administration. Disabling or firewalling Telnet leaves the insecure service installed and re-enableable.

  • ✗

    Audit Telnet connections in Event Viewer

    Why it's wrong here

    Auditing connections records Telnet activity but leaves the insecure service listening and accepting credentials in cleartext. The hardening action is to disable or uninstall Telnet and use SSH or RDP instead. Auditing is the right control when monitoring for suspicious logon activity on an approved service.

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.