The network team opens a firewall ticket asking which hosts should be allowed to reach the management interface of a newly deployed Data Domain. The junior engineer drafts a rule allowing the appliance's management IP from the entire corporate /8, reasoning that nobody will ever file another access ticket again. What is the correct response to that draft?
Select an answer to reveal the explanation.
Short Explanation
A /8 hands the firewall 16 million potential employees for the one box that holds all your backups. Scope admin access to the named admin networks and hosts in your plan, your bastions and monitoring servers, not the whole company just in case. That convenience today is the audit finding later, and you are the one who will own it.
Full Explanation
Management-plane hardening depends on limiting who can reach the management services at all, so the firewall plan for a backup appliance enumerates the administrative networks and hosts that legitimately initiate sessions: the admin VLAN or bastion fleet, monitoring collectors, and any planned automation hosts. Scoping rule sources to that list shrinks the exposed attack surface for the GUI and shell, keeps logging meaningful, and preserves the defense-in-depth pairing of network restriction plus authentication. Restricting to a single port, as in the first proposal, does not cure the wide source: it still exposes an authentication endpoint to every host in a vast range, inviting credential guessing and exploitation against the management stack. The argument that authentication makes source scoping redundant inverts the layers, since authentication is the second gate and is exactly what unauthenticated hosts at scale attack when the first gate is open. Restricting to one named workstation goes too far in the opposite direction: it breaks bastion and monitoring access, is brittle against staff changes, and breeds ad hoc exceptions that erode the rule set. Exam caveat: reconcile the firewall sources with any appliance-side access restrictions as well. Operational check: review the applied rule sources against the as-built admin host list, then attempt management access from an unauthorized subnet and confirm the connection is refused.