ISC2 Systems Security Certified Practitioner (SSCP) Practice Question
During a security review, you inspect the baseline IOS configuration for two layer-3 switches that will sit in an internet-facing DMZ:
line vty 0 4 login local transport input telnet ssh ip http server snmp-server community public RO
To harden the devices before deployment, which single change should be made first to most effectively protect remote administrative sessions from eavesdropping and credential theft?
Remove the ip http server command and restrict the vty lines to SSH version 2 only.
Increase the number of vty lines from five to fifteen to handle concurrent administrators.
Enable spanning-tree portfast on all access interfaces to speed convergence.
Configure a remote syslog destination and increase the local logging buffer size.
The current template allows Telnet and the built-in HTTP server, both of which pass credentials in clear text. Disabling these insecure services and permitting only SSH version 2 provides encrypted, authenticated channels for all remote management traffic, immediately reducing the risk of interception. Simply adding logging, changing portfast, or raising the vty count does not remove the vulnerable protocols, so they leave the largest exposure unaddressed.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
Why is SSH version 2 more secure than Telnet?
Open an interactive chat with Bash
What is the purpose of the ip http server command?
Open an interactive chat with Bash
What does the snmp-server community public RO command do, and why might it need adjustment?
Open an interactive chat with Bash
ISC2 Systems Security Certified Practitioner (SSCP)
Network and Communication Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .