exam questions

Exam 200-301 All Questions

View all questions & answers for the 200-301 exam

Exam 200-301 topic 1 question 566 discussion

Actual exam question from Cisco's 200-301
Question #: 566
Topic #: 1
[All 200-301 Questions]


Refer to the exhibit. Which two commands must be added to update the configuration of router R1 so that it accepts only encrypted connections? (Choose two.)

  • A. transport input ssh
  • B. username CNAC secret R!41!3705926@
  • C. crypto key generate rsa 1024
  • D. line vty 0 4
  • E. ip ssh version 2
Show Suggested Answer Hide Answer
Suggested Answer: AC 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
splashy
Highly Voted 2 years, 1 month ago
Selected Answer: AC
The default setting on switch/router to accept remote access is telnet. Crypto key is not yet generated. "...configuration of router R1 so that it accepts ONLY encrypted connections..." So A + C
upvoted 12 times
...
guynetwork
Highly Voted 2 years, 1 month ago
Selected Answer: AC
A and C only encrypted and crypto key not yet generated
upvoted 8 times
...
W_D
Most Recent 6 months, 1 week ago
A and C I tested in my lab
upvoted 1 times
...
[Removed]
7 months, 2 weeks ago
Selected Answer: AC
A & C are correct
upvoted 1 times
...
[Removed]
1 year, 1 month ago
Selected Answer: BC
B and C must configure
upvoted 1 times
...
shumps
1 year, 1 month ago
C & E is correct
upvoted 1 times
askar430
8 months, 2 weeks ago
ssh1 also enforce encryption but less stronger than ssh2
upvoted 1 times
...
...
kyleptt
1 year, 2 months ago
Selected Answer: AC
C & A must have RSA generated and transport input ssh
upvoted 1 times
...
Liquid_May
1 year, 2 months ago
Selected Answer: AC
The ip ssh version 2 command is optional. The crypto key generate rsa 1024 is required for ssh connections. The transport input ssh command specifies that you only want to connect to the router via ssh, this way you can't connect to the router via Telnet, which doesn't support encrypted connections. Therefore, A and C. Search for Set Up an IOS Router or Switch as SSH Client in this site: https://www.cisco.com/c/en/us/support/docs/security-vpn/secure-shell-ssh/4145-ssh.html
upvoted 3 times
...
Shabeth
1 year, 3 months ago
Selected Answer: AC
A and C
upvoted 2 times
...
ahmadawni
1 year, 3 months ago
Selected Answer: AC
although “crypto key generate rsa” command enables SSH on the device, however the “transport input” command must be entered because ‘The transport command defines which protocols can be used to connect to a line. The default protocol is none, which means that no incoming connections are allowed.’
upvoted 1 times
...
DMc
1 year, 6 months ago
Given answer of C & E is correct. Given answer C & E is probably correct but A & C is good too. Go with C/E because you need C/E first (for encryption) then you do need A for remote access, so focus on “encryption” in the question. https://ipwithease.com/how-to-configure-ssh-version-2-on-cisco-router/
upvoted 2 times
...
creaguy
2 years, 1 month ago
https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_usr_ssh/configuration/15-s/sec-usr-ssh-15-s-book/sec-secure-shell-v2.html#:~:text=the%20default%20host.-,Configuring%20a%20Device%20for%20SSH%20Version%202%20Using%20RSA%20Key%20Pairs,-SUMMARY%20STEPS
upvoted 1 times
...
king_oat
2 years, 1 month ago
Selected Answer: AC
A and C telnet ssh and crypto key not yet created
upvoted 3 times
rogi2023
1 year, 7 months ago
and the cmd "crypto key generate rsa 1024" enables the ssh ver2 by default
upvoted 2 times
...
...
sasquatchshrimp
2 years, 3 months ago
Selected Answer: AD
https://www.firewall.cx/cisco-technical-knowledgebase/cisco-routers/1100-cisco-routers-ssh-support-configuration-rsa-key-generation.html
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago