CompTIA Server+ SK0-005 Practice Question
A systems administrator needs to bring a rack of new virtualization hosts online in a colocation facility. Each server's baseboard management controller (BMC) offers IPMI over a dedicated Ethernet port so the team can power-cycle hosts and launch a remote console after hours. During the security review, the engineer warns that an exposed IPMI interface could serve as an unwanted back-door that bypasses operating-system controls. Which action will BEST preserve the required lights-out capability and reduce the risk of unwanted access?
Disable IPMI completely and use only the host operating system's SSH service for remote administration.
Connect the IPMI ports to the production data LAN and permit inbound UDP 623 from any source.
Enable Cipher 0 in the BMC settings and require complex passwords for all IPMI accounts.
Attach the IPMI ports to a dedicated management VLAN that is reachable only through the company VPN.