QuestionQ172

Security

An engineer deploys a Cisco UCS C-Series Server that must comply with the following security requirements:

  • Unencrypted communication must be disabled.
  • The session timeout must not be more than 15 minutes.
  • Unencrypted traffic must be automatically redirected.
  • CLI-based management must use nondefault ports.

Which configuration set satisfies these requirements?

  • A SSH Enabled SSH Port: 8022 SSH Timeout: 1200 IPMI over LAN Enabled
  • B HTTP Port: 80 / HTTPS Port: 443 Session Timeout: 900 Redirect HTTP to HTTPS Enabled SSH Port: 2022
  • C Redfish Enabled checked Redfish Port: 443 SSH Enabled checked HTTPS Port: 8443
  • D XML API Enabled HTTP Port: 8080 / HTTPS Port: 8443 IPMI over LAN Enabled Randomized Encryption Key
Explanation

A 900-second session timeout equals 15 minutes. Enabling HTTP-to-HTTPS redirection sends HTTP requests to the equivalent encrypted HTTPS address, while SSH port 2022 changes CLI management from the default SSH port of 22. Cisco IMC documents HTTP redirection, session-timeout configuration, and the default SSH port in its communication-services configuration guide.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!