CompTIA Server+ SK0-005 Practice Question
A systems administrator needs to bring a rack of new virtualization hosts online in a colocation facility. Each server's baseboard management controller (BMC) offers IPMI over a dedicated Ethernet port so the team can power-cycle hosts and launch a remote console after hours. During the security review, the engineer warns that an exposed IPMI interface could serve as an unwanted back-door that bypasses operating-system controls. Which action will BEST preserve the required lights-out capability and reduce the risk of unwanted access?
Attach the IPMI ports to a dedicated management VLAN that is reachable only through the company VPN.
Connect the IPMI ports to the production data LAN and permit inbound UDP 623 from any source.
Enable Cipher 0 in the BMC settings and require complex passwords for all IPMI accounts.
Disable IPMI completely and use only the host operating system's SSH service for remote administration.