Cisco CCNA (200-301)IP ServicesMedium

A network administrator is configuring a new Cisco router and needs to ensure that all remote management access is secured using SSH. The router should generate its own RSA key pair for this purpose. Which command sequence will generate the necessary cryptographic keys?

  1. ARouter(config)# crypto key zeroize rsa Router(config)# crypto key generate rsa
  2. BRouter(config)# crypto key generate rsa How many bits in the modulus [512]: 1024
  3. CRouter(config)# crypto key generate rsa general-keys How many bits in the modulus [512]: 1024
  4. DRouter(config)# crypto key generate dsa
Show answer & explanation

Correct answer: C. Router(config)# crypto key generate rsa general-keys How many bits in the modulus [512]: 1024

To generate RSA keys for SSH, the command 'crypto key generate rsa' is used. For modern Cisco IOS, it's best practice to include 'general-keys' to ensure the keys are used for general-purpose RSA operations like SSH. The modulus size should be at least 1024 for security.

Why the other options are wrong

  • A. The 'crypto key zeroize rsa' command deletes existing RSA keys, which is not the goal here. The subsequent 'crypto key generate rsa' is incomplete without specifying modulus size or 'general-keys'.
  • B. This command is correct for older IOS versions, but 'general-keys' is preferred for current versions to ensure the key is suitable for SSH.
  • D. This command generates DSA keys, not RSA keys, and SSH typically uses RSA for host keys.

Cisco IOS RSA Key Generation

The process of creating an RSA public-private key pair on a Cisco device, essential for securing protocols like SSH.

  • Uses 'crypto key generate rsa' command.
  • Requires a hostname and domain name to be configured.
  • Modulus size (e.g., 1024 or 2048) determines key strength.

Memory trick: To make SSH 'secure', you need to 'generate' a 'crypto key' that's 'RSA' and 'general' enough.

More IP Services questions