exam questions

Exam N10-008 All Questions

View all questions & answers for the N10-008 exam

Exam N10-008 topic 1 question 379 discussion

Actual exam question from CompTIA's N10-008
Question #: 379
Topic #: 1
[All N10-008 Questions]

Network traffic is being compromised by DNS poisoning every time a company's router is connected to the internet. The network team detects a non-authorized DNS server being assigned to the network clients and remediates the incident by setting a trusted DNS server, but the issue occurs again after internet exposure. Which of the following best practices should be implemented on the router?

  • A. Change the device's default password.
  • B. Disable router advertisement guard.
  • C. Activate control plane policing.
  • D. Disable unneeded network services.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
fouserd
Highly Voted 1 year, 8 months ago
A) It has to be the default password. Why cause no matter what changes are made, the attacker would go back an ever it if the password has not been changed.
upvoted 12 times
...
Cherubael
Highly Voted 10 months, 3 weeks ago
Selected Answer: A
Most of these are good answers, but HOLY COW! You didn't change the default password!? And you connected it to the internet!?
upvoted 11 times
...
Juliana1017
Most Recent 12 months ago
Selected Answer: A
it is A
upvoted 1 times
...
Dogster
1 year, 2 months ago
Selected Answer: D
ofcourse the default password should be changed, but if we go that road ^^ ya also should have a management vlan and seperate client traffic and so on. changing the default router password won't help when they acces the network trough an open service (port) that isn't used, D is the better answer in this question.
upvoted 1 times
...
famco
1 year, 3 months ago
What a horrible question ! I will go for change default password. Should be done first. Otherwise they might be able to change. But considering there is a firewall it would not be easy Disable unused service: again firewall can block access from internet So, attack is happening from the internet to change the DNS servers. With a firewall it is not easy to attack. I have no clue
upvoted 3 times
...
Cohort07
1 year, 3 months ago
Selected Answer: A
its A. Thats the very first thing you do on any router. No matter what protocols you disable, your password will always be known if you don't change it.
upvoted 3 times
...
Gustitute
1 year, 3 months ago
Selected Answer: D
D is the next best practice. The answer is D according to Chatgpt and my CompTIA review book.
upvoted 1 times
famco
1 year, 3 months ago
I will also go with that. But it's funny that they talk about all the steps to trouble shoot but here we are shooting in the dark with no information available
upvoted 3 times
...
...
RobV
1 year, 3 months ago
Selected Answer: D
Based on the given scenario, the best practice that should be implemented on the router is D. Disable unneeded network services. DNS poisoning occurs when a non-authorized DNS server is assigned to network clients, which may happen when a router is connected to the internet. In this case, the router may be running unnecessary services that can be exploited to facilitate the DNS poisoning attack. Disabling unneeded network services is a good security practice as it reduces the attack surface of the router and limits the potential vulnerabilities that can be exploited by attackers. This can be done by disabling services that are not required for the router's basic functions or services that are not used by the organization. Changing the default password and activating control plane policing are also good security practices, but they may not directly address the issue of DNS poisoning. Router advertisement guard should not be disabled as it is a security feature that helps prevent rogue router advertisements from being sent to the network.
upvoted 3 times
...
MelzTheArtist
1 year, 5 months ago
Selected Answer: D
D. Disable unneeded network services. DNS poisoning occurs when an attacker substitutes a false IP address for a legitimate one in a DNS server's cache. To prevent this type of attack, the router should disable any unneeded network services, including any that might be providing a means for attackers to manipulate the DNS service. By reducing the attack surface, the risk of DNS poisoning attacks can be reduced. Changing the device's default password, disabling router advertisement guard, and activating control plane policing are also important security measures, but they are less relevant to preventing DNS poisoning attacks.
upvoted 4 times
...
BeauChateau
1 year, 6 months ago
Selected Answer: C
I would choose option C as the correct answer. "Activate control plane policing" is a security measure that can help prevent unauthorized access to the router, including DNS poisoning attacks. This feature allows network administrators to set strict access control policies on the router, including the use of specific DNS servers. By activating control plane policing, the network team can ensure that only authorized DNS servers are allowed to access the router, thereby mitigating the risk of DNS poisoning.
upvoted 1 times
...
Paradox_Walnut
1 year, 6 months ago
Selected Answer: A
Agree with everyone's reasoning. Answer is "A".
upvoted 1 times
...
AntonioTech
1 year, 7 months ago
Selected Answer: A
It would've been C if option A hadn't been offered: default password. Every device left with its default password is a huge risk. There are billions of internet devices left with their default passwords and testing a device against its default pass is one of the first things a hacker would do. Thus the answer must be A and not C.
upvoted 4 times
...
TheGinjaNinja
1 year, 8 months ago
A. C is wrong because The Control Plane Policing feature allows users to configure a quality of service (QoS) filter that manages the traffic flow of control
upvoted 5 times
Xigema
1 year, 8 months ago
A is also the conclusion I came to the first time around, because if the router is being compromised every time it's turned on, it leads more towards the router having default credentials
upvoted 7 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...