After an external scan of the civic ASN, a port authority wants layered protection for router control planes without turning the project into a full firewall-centric Security redesign. Which combination best reflects EI defense-in-depth on the network devices?
Select an answer to reveal the explanation.
Short Explanation
Think of the civic ASN like a harbor: one boom at the entrance is not enough. CoPP is the pier gate for the control plane, infrastructure ACLs thin the junk before it arrives, and authenticated sessions keep strangers off the tugs. Layers beat a single firewall hope.
Full Explanation
Enterprise Infrastructure defense-in-depth for routers pairs Control Plane Policing (rate-limit and classify traffic to the RP), infrastructure ACLs that drop or restrict transit/management noise toward control-plane addresses, and control-plane authentication (for example routing protocol auth). That stays in EI scope—hardening network devices—without claiming Firepower/ISE as the core answer. A lone perimeter firewall leaves device control planes exposed. Static-only designs and open SNMPv2c weaken operations and security.