Palo Alto Networks Certified Network Security Administrator (PCNSA)Cybersecurity FundamentalsMedium
A security team is implementing a new policy to ensure that all network devices, including firewalls, routers, and switches, are hardened against common vulnerabilities. Which of the following is a primary security best practice for hardening network devices?
- AUsing default credentials for administrative access.
- BKeeping all unnecessary services and ports open for future use.
- CDisabling all logging to reduce performance overhead.
- DImplementing strong, unique passwords and multi-factor authentication (MFA).
Show answer & explanationAnswer & explanation
Correct answer: D. Implementing strong, unique passwords and multi-factor authentication (MFA).
Implementing strong, unique passwords and multi-factor authentication (MFA) is a fundamental security best practice for hardening network devices, as it significantly reduces the risk of unauthorized access through credential compromise.
Why the other options are wrong
- A. Using default credentials is a major security vulnerability and should always be avoided.
- B. Keeping unnecessary services and ports open increases the attack surface and introduces potential vulnerabilities.
- C. Disabling all logging is a poor practice as it hinders incident response and auditing capabilities.
Device Hardening
The process of securing a system by reducing its attack surface and mitigating potential vulnerabilities.
- Involves removing unnecessary software, services, and accounts.
- Includes applying security patches and updates regularly.
- Requires configuring strong authentication mechanisms and access controls.
- Aims to minimize potential entry points for attackers.
Memory trick: Harden devices like a fortress: strong gates, minimal windows.