Q94Security Fundamentals
Refer to the exhibit. A network administrator has been assigned the task of securing VTY access to a router. Which access-list entry would accomplish this task?
← → navigate · a answer
Community votes
Discussion · 24
32
there is no ssh entry in the table. I didn't understand the answer.
22
"A network administrator has been tasked with securing VTY access to a router".
You need to secure VTY access and also add SSH, not only Telnet.
11
Remember: Among the keywords "eq ssh" does not exist, only "eq telnet". To configure ssh in the ACL we must use only its port number "eq 22". The correct answer is A.
8
"Which access-list entry accomplishes this task" = Which of the lines secures it.
Telnet is trash, but is the only one set up on this access list.
5
Me neither
D 5
Selected Answer: D
Key word: Securing. With telnet you will not accomplish this requirement.
Https and scp doesn't make sense here.
So, I would go with D (ssh) even though the syntax is not fully correct.
A 4
Selected Answer: A
I hate these questions!!!!. A is correct because B, C, and D syntax is wrong. There is no port labeled SCP, HTTPS, or SSH in the cisco command-line.
D 4
Selected Answer: D
D is the best answer. A is logically correct too.
Depending on the router model, IOS supports or does not support keyword SSH.
Considering the shown config already has telnet, we need to add SSH. Hence D.
Please remember, CCNA is an entry level exam, testing our knowledge of basic concepts and rules, especially mechanical memorization of textbook words. For this question, it uses the term 'vty' and wants us to recall that it means 'SSH and Telnet' according to the textbook.
No way that CCNA would test us as deeply as knowing whether SSH is a usable keyword in the port list, not to mention it does exist in some versions of IOS.
In real exams, please stick to basic concepts and rules that you read in the textbook. Don't use real-world experience or real-world logic. CCNA is designed to be a dumb exam. So let's treat it in a dumb way. If you think too much in the real exam, for half of the questions you will find all the four choices are correct, and for the other half you will find all the four choices have some kind of flaw.
D 3
Selected Answer: D
we have to secure the line its ssh
D 2
Selected Answer: D
I think the question is asking what command would you enter from the answers to enable a secure vty connection in which case its always ssh. telnet = not secure
D 2
Selected Answer: D
According to the documentation below, actually there is a SSH keyword (C3 P7)
https://www.cisco.com/c/en/us/td/docs/app_ntwk_services/waas/waas/v401_v403/command/reference/cmdref/ext_acl.pdf
A 2
Selected Answer: A
eq ssh does not exist, you need to specify port 22
A 2
Selected Answer: A
So I verified in GNS3 ACL's don't have SSH , you have to type port 22 in the command, that's why answer D is a trap and A is a valid answer.
D 2
Selected Answer: D
I dont see any answer is correct or the configuration is wrong or the question is wrong. However if you want to secure VTY access(Both Telnet and SSH), D option seems most correct as it allows SSH access to a specific IP group. However only that configuration alone won't work. You have to use the below command as well
line vty 0 15
access-class 101
A 2
Selected Answer: A
"Securing" VTY access can be taken in multiple ways. Are you guaranteeing access through Telnet? If that's how you want to use the word "securing" then sure, but in general, this really is not right as securing means to have a secure connection. Shame on you Cisco.
D 2
Selected Answer: D
Why A is Incorrect:
A. eq telnet (TCP port 23) allows Telnet, which is insecure (no encryption).
The question says "securing," so Telnet should never be picked.
1
I've noticed this is for Extended Access Lists, not standard ACL's.
Google states: "A standard ACL allows or denies traffic access based on the source IP address, while an extended access control list can filter packets with a higher degree of specification. It can determine the types of traffic it allows or blocks beyond just the IP address to include TCP, ICMP, and UDP, for example."
Maybe that's why SSH appears as a CLI TCP Keyword.
1
Router(config)#access-list 101 permit tcp any 10.0.1.1 0.0.0.0 eq ssh
^
% Invalid input detected at '^' marker.
1
Going with D
1
The correct choice is D.
The acces via telnet is already secured via eq telnet. Its posible to type telnet after eq on the extended acl (see pag. 50 CCNA 200-301 Official Cert Guide, Volume 2) then we only have to secure via ssh.
1
But they said refer to the exhibit
1
try to read other questions before answering because it's very tricky most of the questions vision test i played with it many many times and still
1
there's no SSH with the ACL above i choose that too then i checked the people why and found there's no SSH
A 1
Selected Answer: A
Just to make it clear, the reason WHY it's A is because there is NO ACL that has SSH in it. Therefore, you HAVE to use the TELNET option to be used to then use it to THEN access the device to THEN use it to SECURE it. THEN you can add in an ACL SSH and further put in SSH lockdown. For now, the ONLY way you're gonna be able to gain access to be able to do anything is via the TELNET option. There is NO ACL that even ALLOWS SSH