A vulnerability scan flags the appliance's management web service for supporting obsolete TLS protocol versions. What is the correct hardening direction for the management plane?
Select an answer to reveal the explanation.
Short Explanation
A service that still speaks old TLS is a vault with a biometric lock on the door and a 1980s padlock propped beside it — the scanner goes for the old one every single time. Hardening your management plane means switching off what it's willing to speak and keeping only what's current. And don't trust the checkbox: verify with the same kind of probe the scanner used on yours.
Full Explanation
Management-plane hardening works by shrinking what a service is willing to negotiate. Obsolete TLS versions carry well-known cryptographic weaknesses, and a web service that still accepts them will happily complete a degraded handshake with a scanner or an adversary, regardless of the strength also offered. Where the platform exposes protocol selection, disable the obsolete versions so only current ones remain enabled, then prove the change from outside — a fresh handshake attempt or a repeat scan showing the old versions refused — because configuration intent and enforced behavior are different facts. Reinstalling from factory media fails by mechanism: protocol enablement is runtime configuration, not a baked-in constant, and a reinstall would discard other settings while restoring the very defaults that were flagged. VLAN isolation as a blanket answer fails defense-in-depth: segmentation is one control protecting one path, while administrators' workstations traverse that VLAN daily, and a weak handshake negotiated by an authorized client is still a weak handshake. A no-listener posture may suit extreme postures but does not answer the finding as stated — the management web service is a required deployed function, and removing it is an outage disguised as hardening. Exam caveat: record which protocol versions remain enabled so future scans have a baseline to be compared against. Operational check: re-run the original probe from an administration host, confirm the obsolete versions are refused, and file the accepted set in the hardening record.