Q116Security Fundamentals
An engineer needs to configure R1 for a new user account. The account must meet these requirements: - It must be configured in the local database. - The username is engineer2. - It must use the strongest configurable password. Which command must the engineer configure on the router?
← → navigate · a answer
Community votes
Discussion · 19
14
A.
CAT9200(config)#username engineer2 privilege 1 password 7 test2021
Invalid encrypted password: test2021
B.
CAT9200(config)#username engineer2 secret 4 $1$b1Ju$kZbBS1Pyh4QzwXyZ
ERROR: Type 4 passwords have been deprecated.
Migrate to a supported password type
C.
CAT9200(config)#username engineer2 algorithm-type scrypt secret test2021
CAT9200(config)#do show run | inc engineer2
username engineer2 secret 9 $9$2FTH4wYx6hzf1X$1WVSI21bbXZ7JlP5v42YDvImoHd6DTHW5pcm4J0Iy8A
CAT9200(config)#
D.
CAT9200(config)#username engineer2 secret 5 password $1$b1Ju$kZbBS1Pyh4QzwXyZ
% Ambiguous command: "username engineer2 secret 5 password $1$b1Ju$kZbBS1Pyh4QzwXyZ"
CAT9200(config)#
The only opcion that works is opcion C. I set the user and pass, and when I ran "show run", the passsword was encrypted.
6
actually i take that back, i tested it on a real device and C works.
I guess it's C then, my bad!
C 4
Selected Answer: C
C is the strongest password, type 9 and SHA-256 algorithm.
CCNA 200-301 Official Cert Guide, Volume 2 page 93
https://community.cisco.com/t5/networking-knowledge-base/understanding-the-differences-between-the-cisco-password-secret/ta-p/3163238
3
algorithm-type scrypt: This says which algorithm is used for password hashing, and in this case it is "scrypt". "scrypt" is a password-based key derivation function that is made to be highly resistant to brute force attacks.
B 3
Selected Answer: B
B looks like it meets all those conditions.
C 3
Selected Answer: C
As of bug CSCue95644 (which is a Cisco issue identifier), keyword 4 for specifying a SHA-256 encrypted secret string has been deprecated. This shows that the use of that specific encryption algorithm type is no longer recommended or supported by Cisco.
https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/security/d1/sec-d1-cr-book/sec-cr-e1.html#:~:text=4%20keyword%20is-,deprecated,-.
The syntax of letter C is correct, only the password "test2021" would be weak, but as shown is just a "test" password, it will not be this password that the engineer will hand over to the user, without a crisis. However, setting the password with type 9 (SCRYPT) is the strongest that can be set, better than 5 and 8. The old type 4 is no longer recommended due to its fragility (bug CSCue95644).
B 2
Selected Answer: B
B is right, C uses a very common password and cannot be correct!!
C 2
Selected Answer: C
https://www.linkedin.com/pulse/enable-secret-password-algorithms-md5-sha256-scrypt-michael-akintola
C 2
Selected Answer: C
scrypt is the best algorithm-type. No doubt about it.
It doesn't matter how long the password is - it's mainly about the algorithm.
C 2
Selected Answer: C
I would say the correct answer is C
A & D use the default encryption with the md5 hashing algorithm, which is not secure and has been exploited for years.
C uses scrypt as the hashing algorithm, which is a type 9 encryption algorithm and it's more secure than md5
B is missing the password keyword
https://www.linkedin.com/pulse/enable-secret-password-algorithms-md5-sha256-scrypt-michael-akintola
C 2
Selected Answer: C
scrypt is stronger than the PBK... algorithm on B
C 2
Selected Answer: C
The right answer is **C. R1(config)# username engineer2 algorithm-type scrypt secret test2021**.
### Explanation:
- The **`username`** command configures a local user account on the router.
- The **`secret`** keyword means the password will be hashed and kept securely.
- The **`algorithm-type scrypt`** sets the Scrypt algorithm, which is the strongest password hashing algorithm available for local user accounts on Cisco devices.
Option C is the correct one because it uses the `algorithm-type scrypt` parameter, making sure the password is configured with the most secure hashing algorithm. The password `test2021` is used, and the `secret` keyword makes sure it is hashed securely.
1
Command: username engineer2 algorithm-type scrypt secret test2021 is not know in PT.
1
if strongest password - answer D
if strongest store password - C
I dont understhand what Cisco want
B 1
Selected Answer: B
B. R1(config)# username engineer2 secret 4 $1$b1Ju$kZbBS1Pyh4QzwXyZ
This command makes a local user account named "engineer2" and sets the password to the given encrypted string "$1$b1Ju$kZbBS1Pyh4QzwXyZ". The "secret" keyword is used to indicate the encrypted password. The "4" shows the encryption type, which in this case seems to be MD5.
Option A uses the "password" keyword, which means a simple, unencrypted password. Option C uses the "algorithm-type scrypt" which is not needed for this scenario, and Option D is wrong because it uses the wrong keyword ("password") instead of "secret" for specifying an encrypted password.
1
I tried every command on GNS3 Cisco C3725 router, all are wrong.
B 1
Selected Answer: B
The phrase "It must use the strongest password configurable" suggests that the user account should have the most secure and strong password possible, not necessarily the strongest encryption for the password itself. It means that the user's password should be as complex, long, and difficult to guess as possible, following best practices for password security.
B 1
Selected Answer: B
A -> ERROR: Can not have both a user password and a user secret.
Please select one or the other.
B -> works
C -> username engineer2 algorithm-type scrypt secret test2021
^
% Invalid input detected at '^' marker.
D -> username engineer2 secret 5 password $1$b1Ju$kZbBS1Pyh4QzwXyZ
^
% Invalid input detected at '^' marker.
(in D, 'password' would be the password, and the rest is just gibberish)
1
btw this was tested in packet tracer real quick. Just do it in 2 minutes and wou'll get your answer