ETExamTower
Q18Security FundamentalsMultiple answers

What are two recommendations for protecting network ports from being exploited when they are located in an office space outside an IT closet? **(Choose two.)**

Select 2 answers.
← → navigate · a answer
Community votes
E
50% (4)
D
38% (3)
B
13% (1)
A
0% (0)
C
0% (0)
Discussion · 5
11
I was thinking static ARP entries would also stop ports from being exploited, but I guess the other two are actually the better choices.
7
checked and it is correct answers DE
D, E 3
Selected Answer: DE This may help: https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_usr_8021x/configuration/xe-3se/3850/sec-user-8021x-xe-3se-3850-book/config-ieee-802x-pba.html
B, E 2
Selected Answer: BE B and E are the best choices. D is secure, but unrealistic. It's not that you want it and you can have it. Port-based authentication means using 802.1x with a RADIUS or TACACS server. It really depends on your current infrastructure and budget. Applying 802.1x to every endpoint in an organisation takes a huge amount of work, and cuts flexibility in daily operation. If a network already has port-based authentication, very good, keep using it. If it doesn't have it yet, no need to push yourself to use it. You would need to set up an AAA server, install certificates on endpoints, configure the switch, and each time a device is moved or changed you have to reconfigure it. B can effectively block most unauthorised devices from connecting to the network. E removes the connectivity from the root. These are realistic methods in real work.
D, E 1
Selected Answer: DE Port-based authentication = 802.1x (RADIUS/TACACS+) - IEEE 802.1X port-based authentication is set up on a device to stop unauthorized devices (supplicants) from getting access to the network. The device can combine the role of a router, switch, and access point, depending on the fixed configuration or installed modules. The switch functions are supplied by either built-in switch ports or a plug-in module with switch ports. This feature supports both access ports and trunk ports. LINK: https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_usr_8021x/configuration/xe-3se/3850/sec-user-8021x-xe-3se-3850-book/config-ieee-802x-pba.html