exam questions

Exam N10-008 All Questions

View all questions & answers for the N10-008 exam

Exam N10-008 topic 1 question 62 discussion

Actual exam question from CompTIA's N10-008
Question #: 62
Topic #: 1
[All N10-008 Questions]

A network engineer configured new firewalls with the correct configuration to be deployed to each remote branch. Unneeded services were disabled, and all firewall rules were applied successfully. Which of the following should the network engineer perform NEXT to ensure all the firewalls are hardened successfully?

  • A. Ensure an implicit permit rule is enabled
  • B. Configure the log settings on the firewalls to the central syslog server
  • C. Update the firewalls with current firmware and software
  • D. Use the same complex passwords on all firewalls
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
veli_117
Highly Voted 2 years, 1 month ago
Selected Answer: B
C is WRONG: https://www.fortinet.com/resources/cyberglossary/firewall-configuration Update the firmware has to be the very first step, obviously. Step 4: Configure Other Firewall Services and Logging
upvoted 15 times
Nafbon
1 year, 1 month ago
Correct answer==B, Just after configuring all necessary things, the next step is to simply configure the log settings on the firewalls to the central Syslog server.
upvoted 1 times
...
MitchF
1 year, 8 months ago
C is CORRECT based on your argument. It should have been done first, but it was clearly not done yet. You can't "assume" this task was completed, when the question doesn't say so. In real life too, you can't "assume" that a tech updated the firewall, when nothing was mentioned in the ticketing system about it. Your manager will be upset if you "assume" work was done, without "knowing".
upvoted 12 times
...
Jacko666
2 years, 1 month ago
Well as they've not already done it, they should be doing it next..no?
upvoted 5 times
Gustitute
2 years ago
I think it is implied that firmware updates are included in the aforementioned configuration. This is the sort of thing that trips me up on tests though. It's not the best worded question IMO.
upvoted 3 times
Gustitute
2 years ago
I was wrong on this actually. Setting the logs is important for monitoring but not necessarily directly for hardening. I think the answer CompTIA is looking for is C.
upvoted 6 times
...
...
...
...
comeragh
Highly Voted 1 year, 12 months ago
Selected Answer: C
I would tend to go with C here. I don't feel configuring log settings relates to hardening a firewall. Open to correction here and just my thoughts.
upvoted 10 times
MitchF
1 year, 8 months ago
I agree. Configuring logs does nothing to harden a system. They should have updated the firmware, but they didn't do it yet in the question, so it needs to be done before sending the device out (I am an jr. I.T. Systems Integrator)
upvoted 4 times
...
...
JJay99
Most Recent 2 months, 2 weeks ago
Selected Answer: C
You should confirm if your system is up to date always......logging is a good practice but it's all for clarity, it does not prevent vulnerabilities.
upvoted 1 times
...
crazymonkeh
8 months, 3 weeks ago
Selected Answer: C
The question is asking which would "harden" the firewall. Syslog are just logs. Although it's important, and must be done, it has nothing to do with the aforementioned question. Updates are always a way to harden systems and applications. The answer is "C"
upvoted 2 times
...
ChillyP
9 months ago
B doesn't 'harden' the firewall. It simply gives you oversite, monitoring and audit capabilities, yes it helps with overall security but doesn't physically harden the firewall itself. Firmware updates however will harden and patch the firewall. Answer is C in my opinion.
upvoted 1 times
...
stanislaus450
1 year ago
Selected Answer: B
To ensure that all the firewalls are hardened successfully after configuration, the network engineer should perform the following step next: B. Configure the log settings on the firewalls to the central syslog server Configuring the log settings to send firewall logs to a central syslog server enables centralized monitoring and analysis of security events and policy violations across all firewall devices. This allows for better visibility into potential security threats and helps ensure that the firewalls are effectively protecting the network. Therefore, configuring log settings to send logs to a central syslog server would be the appropriate next step to ensure that all firewalls are hardened successfully.
upvoted 1 times
...
Bo_Knows
1 year, 2 months ago
Selected Answer: C
keyword hardened, next step to hardening only with answer C
upvoted 2 times
...
NASIR0CITV
1 year, 2 months ago
To ensure the best security and performance, it is generally recommended to update the firewalls with current firmware and software before configuring the firewall rules. This allows you to start with a secure and stable foundation and ensures compatibility between the firmware/software and the firewall rules.
upvoted 1 times
daddylonglegs
1 year ago
Agreed, I've seen instances where upgrading firmware on a firewall completely wiped out the configured firewall rules (which it obviously should not do). If it were me, upgrading to current firmware would be the first step with a new firewall.
upvoted 1 times
...
...
smarvin
1 year, 2 months ago
C seems to be the correct answer here: "... new firewalls with the correct configuration to be deployed" implies that the firewall has not yet been deployed, so the next step would be to update the firmware before putting it into a production environment. Logging is not a hardening technique.
upvoted 1 times
...
amsterdam24
1 year, 3 months ago
With the previous exams, I believe that word "hardened" associates with "updates" in comptia
upvoted 2 times
...
amsterdam24
1 year, 3 months ago
Selected Answer: C
Guys comptia trying to confuse, but there is a signs "configured new firewalls with the correct configuration" to be deployed to each remote branch After configuring new firewalls with the correct settings and disabling unneeded services, the next step to ensure that all the firewalls are hardened successfully should be: C. Update the firewalls with current firmware and software
upvoted 3 times
...
Andylove
1 year, 4 months ago
Selected Answer: B
Configure Log Settings (B): Configuring log settings is crucial for monitoring and auditing the firewall's activity. By sending logs to a central syslog server, the network engineer can have a centralized view of firewall events, aiding in troubleshooting and security analysis.
upvoted 1 times
...
jeanj
1 year, 6 months ago
i think its C because of the key word hardend
upvoted 1 times
...
I_Know_Everything_KY
1 year, 6 months ago
Selected Answer: C
Clue is "Hardening". While logging is important, it doesn't fit the question here.
upvoted 2 times
daddylonglegs
1 year ago
Log management is definitely important in network hardening.
upvoted 1 times
...
...
Coolwolf
1 year, 6 months ago
B sounds logical to me
upvoted 1 times
...
TacosInMyBelly
1 year, 6 months ago
Selected Answer: C
Patching will update to the most up to date SW
upvoted 3 times
...
Itzhavok
1 year, 7 months ago
Selected Answer: C
This is a hardening question not a protocol question.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago