Remember: Among the keywords "eq ssh" does not exist, only "eq telnet". to configure ssh in the ACL we must use only its port number "eq 22". Answer correct is A.
in Pt no but in real life you can
https://www.cisco.com/c/en/us/td/docs/app_ntwk_services/waas/waas/v431/command/reference/cmdref/ext_acl.html
i vote for ssh
"Which access-list entry accomplishes this task" = Which of the lines does secure it.
Telnet is trash, but is the only one configured on this access list.
"Securing" VTY access can be interpreted multiple ways. Are you guaranteeing access through Telnet? If that's how you want to use the word "securing" then sure, but in general, this really is not correct as securing means to have a secure connection. Shame on you Cisco.
I dont see any answer is correct or configuration is wrong or question is wrong. However if you want to secure VTY access(Both Telnet and SSH), D option seems most correct as it allow SSH access to specific ip group. However only that configuration only won't work. You have to use below command as well
line vty 0 15
access-class 101
D is the best answer. A is logically correct as well.
Depending on the model of the router, IOS supports or does not support keyword SSH.
Considering the displayed config already has telnet, we need to add SSH. Hence D.
Please remember, CCNA is an entry level exam, testing our knowledge of basic concepts and rules, especially mechanical memorisation of textbook words. For this question, it uses the term 'vty' and wants us to recall that it means 'SSH and Telnet' according to the textbook.
No way that CCNA would test us as deep as knowing whether SSH is a usable keyword in the port list, not to mention it does exist in some versions of IOS.
In real exams, please stick to basic concepts and rules that you read in the textbook. Don't use real-world experience or real-world logic. CCNA is designed to be a dumb exam. So let's treat it a dumb way. If you think too much in the real exam, for half of the questions you will find all the four choices are correct, and for the other half you will find all the four choices have some kind of flaw.
The correct choice is D.
The acces via telnet is already secured via eq telnet. Its posible to type telnet after eq on the extended acl (see pag. 50 CCNA 200-301 Official Cert Guide, Volume 2) then we only have to secure via ssh.
it´s A
I have tested o a real router, SSH at the of the command is not acceptable, it must be eq 22
But telnet at the end of the command is acceptable.
Key word: Securing. With telnet you will not accomplish this requirement.
Https and scp doesn't make sense here.
So, I would go with D (ssh) even though the syntax is not fully correct.
The issue with this question is that it's ambiguous as to whether it's asking us to identify an existing command in the configuration, or suggest an additional one.
In the first case, the answer is obviously A. In the second case, it's obviously D.
The problem is worsened by the fact that Telnet isn't a secure protocol, and allowing only Telnet access is arguably not "securing" anything, favoring SSH.
So I chose D, but it could easily be A. Both are arguably correct.
I hate these questions!!!!. A is correct because B, C, and D syntax is incorrect. There is no port labeled SCP, HTTPS, or SSH in the cisco command-line.
According to the documentation below, actually there is a SSH keyword (C3 P7)
https://www.cisco.com/c/en/us/td/docs/app_ntwk_services/waas/waas/v401_v403/command/reference/cmdref/ext_acl.pdf
I've noticed this is for Extended Access Lists, not standard ACL's.
Google states: "A standard ACL allows or denies traffic access based on the source IP address, while an extended access control list can filter packets with a higher degree of specification. It can determine the types of traffic it allows or blocks beyond just the IP address to include TCP, ICMP, and UDP, for example."
Maybe that's why SSH shows up as a CLI TCP Keyword.
I think the question is asking what command would you enter from the answers to enable a secure vty connection in which case its always ssh. telnet = not secure
This section is not available anymore. Please use the main Exam Page.200-301 Exam Questions
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
bootloader_jack
Highly Voted 3 years, 7 months agodropspablo
1 year, 8 months ago[Removed]
1 year, 4 months agokadamske
3 years, 7 months agokokoyul
Highly Voted 3 years, 7 months agotestssssssss
3 years, 3 months agoschmidt97
9 months, 2 weeks agodsmitd33
Most Recent 2 weeks, 6 days agoriteshm42
2 months agoSimrankoor
5 months, 1 week agoMinSun600
3 months agoJoshua25
6 months, 2 weeks agoMinSun600
3 months agomatass_md
9 months, 2 weeks agojuliomugarra
11 months, 1 week ago[Removed]
1 year agof2faf2e
1 year, 2 months agoa67c04a
1 year, 2 months agoricky1802
1 year, 3 months ago[Removed]
1 year, 4 months agopicho707
1 year, 5 months agomapicoli
1 year, 6 months agofmaquino
1 year, 7 months agoPerra
1 year, 6 months agoshaney67
1 year, 7 months ago