Limiting Cisco Router Attack Surface: Global Commands

Describe CIS benchmarks for hardening devices such as Cisco Secure Firewall (FTD) and Cisco IOS XE
Answer Correct answer: C, D — Implement no cdp run and no ip http server to disable discovery and web management services on an internet-facing router.

Which two global commands must the network administrator implement to limit the attack surface of an internet-facing Cisco router? (Choose two.)

  1. service tcp-keepalives-in
  2. no service password-recovery
  3. no cdp run Correct Answer
  4. no ip http server Correct Answer
  5. ip ssh version 2

Community Votes

CD
100%

100% of anonymous learners picked answer CD. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests CIS hardening principles for perimeter devices, specifically focusing on disabling unused or risky services to reduce the number of potential entry points for attackers.

To limit the attack surface of an internet-facing Cisco router, administrators must disable unnecessary services like HTTP and protocols that leak topology information like CDP. The correct global commands are no cdp run and no ip http server.

Candidates often select 'ip ssh version 2' because it is a security best practice; however, enabling/configuring SSH version 2 does not reduce the attack surface itself, as the service would likely already be running or enabled in version 1.

Community Discussion (6 comments)

madboy2 👍 1 Selected: CD
CDP (Cisco Discovery Protocol) exposes device information (e.g., IP addresses, model, OS version) to potential attackers. The HTTP server allows web-based management, which is a security risk if left open to the internet. Therefore C and D should be correct
Pierre_Bouvier 👍 1 Selected: CD
ip ssh version 2: Configures SSH version 2 for secure remote management. While it improves security, it does not directly reduce the attack surface.
Surfside92 👍 1 Selected: CD
ssh ver 2 is more secure - but you're not limiting the remote access attack surface by using it over version 1
Premium_Pils 👍 1
C - no Ip http server to disable unused services. D - ip ssh version 2 for enhanced security features.
klu16 👍 1 Selected: CD
I will go with C and D. "ip ssh version 2" ensures that SSH version 2 is used, but that does not limit the attack surface, though.
devildog 👍 1
I could be wrong, but I'm thinking C. and D.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Disabling Cisco Discovery Protocol (CDP) with 'no cdp run' prevents the router from advertising its identity, IP addresses, and capabilities to neighbors, which is critical for an internet-facing device to avoid reconnaissance. Disabling the HTTP server with 'no ip http server' removes an unencrypted web management interface that could be exploited if left active. These two actions directly eliminate services that increase the attack surface.

Why the Other Options Are Wrong

'Service tcp-keepalives-in' is a diagnostic tool for detecting dead TCP connections and does not reduce the attack surface. 'No service password-recovery' restricts administrative access to the device during recovery scenarios but does not mitigate external network attacks. 'Ip ssh version 2' enforces a secure protocol version, but if SSH is not already enabled or if the focus is strictly on limiting the surface (number of open ports/services), simply configuring the version doesn't close a door that is already open or closed by other means; more importantly, compared to turning off HTTP and CDP, it's less about reducing exposure and more about securing an existing connection.

Community Comment Notes

The community consensus strongly favors options C and D. As madboy2 noted, "CDP exposes device information... The HTTP server allows web-based management, which is a security risk." Pierre_Bouvier correctly identified that while SSH v2 is secure, it "does not directly reduce the attack surface" in the same way disabling unused services does.

Exam Strategy

When asked to limit the attack surface, prioritize disabling any service that is not explicitly required for business operations. Look for commands that turn off discovery protocols (CDP, LLDP) and unused management interfaces (HTTP, Telnet).

Frequently Asked Questions

Why isn't ip ssh version 2 the correct answer?

Configuring SSH version 2 secures the protocol but does not reduce the attack surface by closing a service port or hiding device info like CDP or HTTP do.

Does no service password-recovery limit the attack surface?

No, it prevents unauthorized physical access to recover passwords but does not mitigate remote network-based attacks or reduce the number of active services.

Related Analysis

← Back to 350-701 Study Guide