Cisco CCNA (200-301)IP ServicesEasy
A network security audit requires that all management access to network devices be encrypted and secure. Which protocol should be enabled on Cisco devices for remote command-line interface (CLI) access, and which port does it typically use?
- ASSH, Port 22
- BHTTP, Port 80
- CSNMP, Port 161
- DTelnet, Port 23
Show answer & explanationAnswer & explanation
Correct answer: A. SSH, Port 22
SSH (Secure Shell) provides a secure, encrypted connection for remote command-line access to network devices, typically using TCP port 22. Telnet is insecure, and HTTP/SNMP are for web management and network monitoring, respectively.
Why the other options are wrong
- B. HTTP is for web-based management, not CLI, and is unencrypted.
- C. SNMP is for network monitoring and management, not interactive CLI access, and uses UDP ports 161/162.
- D. Telnet uses Port 23 but transmits data in plaintext, which is not secure.
Secure Remote CLI Access
Using encrypted protocols to manage network devices remotely via the command-line interface.
- SSH is the industry standard for secure CLI access.
- Encrypts all data, including credentials.
- Typically uses TCP port 22.
Memory trick: For secure remote control, SSH is the only choice for the shell.