Cisco CCNA (200-301)Security FundamentalsHard
An engineer runs 'enable algorithm-type scrypt secret Cisco123' on a router and then reviews the running-config, seeing 'enable secret 9 $9$abcDEF...'. Compared to the older Type 5 enable secret hash, what security advantage does this Type 9 hash provide?
- AIt reversibly encrypts the password so it can be decrypted by the router if needed
- BIt transmits the password in cleartext across the network for compatibility
- CIt uses a computationally expensive algorithm (scrypt) that resists brute-force and GPU-based cracking better than MD5-based Type 5
- DIt stores the password using the same weak algorithm as Type 7, just with longer key length
Show answer & explanationAnswer & explanation
Correct answer: C. It uses a computationally expensive algorithm (scrypt) that resists brute-force and GPU-based cracking better than MD5-based Type 5
Type 9 passwords use the scrypt key derivation function, which is intentionally slow and memory-hard, making brute-force and GPU/ASIC-based cracking attacks far less practical than against Type 5 (MD5-based) hashes. Neither Type 5 nor Type 9 are reversible; both are one-way hashes, unlike the reversible Type 7 encryption.
Why the other options are wrong
- A. Type 9 hashes are one-way and cannot be decrypted, unlike Type 7 encryption.
- B. Passwords are never sent in cleartext regardless of hash type used in local config.
- D. Type 7 uses a simple reversible Vigenere-like cipher, which is far weaker and unrelated to scrypt.
Type 9 (scrypt) Secret
Type 9 enable/user secrets use the scrypt hashing algorithm, which is computationally and memory intensive, making them much harder to brute-force than Type 5 MD5-based hashes.
- Type 5 = MD5-based hash, faster to crack with modern hardware
- Type 9 = scrypt-based hash, resistant to GPU/ASIC cracking
- Type 7 is reversible and considered very weak, unrelated to Type 9
Memory trick: Type 9 is the slow tortoise that outlasts crackers; Type 7 is a paper lock.