Cisco CCNA (200-301)Security FundamentalsHard

An engineer configures 'enable secret Cisco123' on a router that already has 'enable password Cisco123' configured. A colleague later runs 'show running-config' and notices the enable password line is still readable in plaintext even though 'service password-encryption' is enabled. Which statement explains this scenario?

  1. AThe enable secret uses a stronger one-way hash and takes precedence for login, while service password-encryption only applies a weak reversible Type 7 obfuscation to the enable password
  2. BThe enable secret is ignored whenever an enable password also exists
  3. CBoth passwords will always be identical, so this behavior is expected
  4. Dservice password-encryption failed because two passwords cannot coexist on the same device
Show answer & explanation

Correct answer: A. The enable secret uses a stronger one-way hash and takes precedence for login, while service password-encryption only applies a weak reversible Type 7 obfuscation to the enable password

When both are configured, the router uses the enable secret (a strong MD5/Type 5 or SHA hash) for authentication and ignores the enable password for login purposes. However, 'service password-encryption' only applies a weak, easily reversible Type 7 encoding to plaintext passwords like the enable password, not the already-hashed enable secret.

Why the other options are wrong

  • B. The enable secret takes precedence for authentication, it is not ignored.
  • C. They are independently configured and need not match.
  • D. Both commands can coexist; there's no failure here.

enable secret vs enable password

enable secret uses a strong one-way hash (Type 5/8/9) and takes precedence over enable password, which is stored in weaker, reversible Type 7 form when service password-encryption is enabled.

  • enable secret always overrides enable password for authentication
  • service password-encryption applies weak Type 7 to plaintext passwords
  • Type 7 is easily reversible; Type 5/8/9 hashes are much stronger

Memory trick: Secret is Strong, Service is Sloppy (Type 7)

More Security Fundamentals questions