Q7Security DesignMultiple answers
Which three measures do you recommend to harden the control plane of an infrastructure device? (Choose three.)
Select 3 answers.
← → navigate · a answer
Community votes
Discussion · 9
A, C, F 9
Selected Answer: ACF
I think it is A C F too
5
ACF for sure
4
C, F is correct for sure , it's very interesting as A,B and D are related to management plane, also E is not part from any
2
ACF is the ans
A, C, F 2
Selected Answer: ACF
ACF, warning banner, is for legal issues, but don't provide any security
A, C, F 2
Selected Answer: ACF
A. SNMPv3: SNMPv3 is the latest version of the Simple Network Management Protocol (SNMP) and gives secure authentication and encryption for monitoring and managing network devices. It is recommended to use SNMPv3 for control plane security.
C. Routing protocol authentication: Adding authentication mechanisms, such as MD5 or SHA, for routing protocols helps ensure that only trusted devices can take part in the routing process. This helps prevent unauthorized devices from injecting false or malicious routing information.
F. Control Plane Policing (CoPP): CoPP is a mechanism that lets you control and prioritize traffic destined for the control plane of a network device. By applying policies to limit the rate and types of traffic allowed to reach the control plane, CoPP helps protect the control plane from resource exhaustion and denial-of-service (DoS) attacks.
1
BCF
https://www.cisco.com/c/en/us/support/docs/ip/access-lists/13608-21.html#anc39
A, D, F 1
Selected Answer: ADF
Snmpv3 for control plane security is fine
Redunandt aaa for accessing and logging security log
CoPP is self explanatory
1
Yes, ACF is the way to go.