Limiting Cisco Router Attack Surface: Global Commands
Which two global commands must the network administrator implement to limit the attack surface of an internet-facing Cisco router? (Choose two.)
Community Votes
100% of anonymous learners picked answer CD. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests CIS hardening principles for perimeter devices, specifically focusing on disabling unused or risky services to reduce the number of potential entry points for attackers.
To limit the attack surface of an internet-facing Cisco router, administrators must disable unnecessary services like HTTP and protocols that leak topology information like CDP. The correct global commands are no cdp run and no ip http server.
Candidates often select 'ip ssh version 2' because it is a security best practice; however, enabling/configuring SSH version 2 does not reduce the attack surface itself, as the service would likely already be running or enabled in version 1.
Community Discussion (6 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Disabling Cisco Discovery Protocol (CDP) with 'no cdp run' prevents the router from advertising its identity, IP addresses, and capabilities to neighbors, which is critical for an internet-facing device to avoid reconnaissance. Disabling the HTTP server with 'no ip http server' removes an unencrypted web management interface that could be exploited if left active. These two actions directly eliminate services that increase the attack surface.Why the Other Options Are Wrong
'Service tcp-keepalives-in' is a diagnostic tool for detecting dead TCP connections and does not reduce the attack surface. 'No service password-recovery' restricts administrative access to the device during recovery scenarios but does not mitigate external network attacks. 'Ip ssh version 2' enforces a secure protocol version, but if SSH is not already enabled or if the focus is strictly on limiting the surface (number of open ports/services), simply configuring the version doesn't close a door that is already open or closed by other means; more importantly, compared to turning off HTTP and CDP, it's less about reducing exposure and more about securing an existing connection.Community Comment Notes
The community consensus strongly favors options C and D. As madboy2 noted, "CDP exposes device information... The HTTP server allows web-based management, which is a security risk." Pierre_Bouvier correctly identified that while SSH v2 is secure, it "does not directly reduce the attack surface" in the same way disabling unused services does.Exam Strategy
When asked to limit the attack surface, prioritize disabling any service that is not explicitly required for business operations. Look for commands that turn off discovery protocols (CDP, LLDP) and unused management interfaces (HTTP, Telnet).
Frequently Asked Questions
Why isn't ip ssh version 2 the correct answer?
Configuring SSH version 2 secures the protocol but does not reduce the attack surface by closing a service port or hiding device info like CDP or HTTP do.
Does no service password-recovery limit the attack surface?
No, it prevents unauthorized physical access to recover passwords but does not mitigate remote network-based attacks or reduce the number of active services.