Palo Alto Networks Certified Network Security Administrator (PCNSA)Cybersecurity FundamentalsMedium

A security team is implementing a new policy to ensure that all network devices, including firewalls, routers, and switches, are hardened against common vulnerabilities. Which of the following is a primary security best practice for hardening network devices?

  1. AUsing default credentials for administrative access.
  2. BKeeping all unnecessary services and ports open for future use.
  3. CDisabling all logging to reduce performance overhead.
  4. DImplementing strong, unique passwords and multi-factor authentication (MFA).
Show answer & explanation

Correct answer: D. Implementing strong, unique passwords and multi-factor authentication (MFA).

Implementing strong, unique passwords and multi-factor authentication (MFA) is a fundamental security best practice for hardening network devices, as it significantly reduces the risk of unauthorized access through credential compromise.

Why the other options are wrong

  • A. Using default credentials is a major security vulnerability and should always be avoided.
  • B. Keeping unnecessary services and ports open increases the attack surface and introduces potential vulnerabilities.
  • C. Disabling all logging is a poor practice as it hinders incident response and auditing capabilities.

Device Hardening

The process of securing a system by reducing its attack surface and mitigating potential vulnerabilities.

  • Involves removing unnecessary software, services, and accounts.
  • Includes applying security patches and updates regularly.
  • Requires configuring strong authentication mechanisms and access controls.
  • Aims to minimize potential entry points for attackers.

Memory trick: Harden devices like a fortress: strong gates, minimal windows.

More Cybersecurity Fundamentals questions