Which protocol is preferred over Telnet for remote CLI management because it encrypts the session?
SSH (Secure Shell) provides an encrypted, authenticated remote CLI session over TCP port 22, protecting both login credentials and subsequent commands from eavesdropping or session hijacking. It is the industry-standard replacement for Telnet because it ensures confidentiality and integrity of the management traffic on untrusted networks. Unlike the other options, SSH is purpose-built for secure interactive terminal access to network devices.
Why this answer
SSH encrypts credentials and management traffic, making it the standard secure replacement for Telnet.
Exam trap
A frequent exam trap is selecting Telnet or other protocols like FTP or TFTP for remote CLI management because they are familiar or commonly mentioned in networking contexts. Telnet is often mistakenly chosen because it provides remote access, but it sends all data unencrypted, exposing credentials to attackers. FTP and TFTP are file transfer protocols and do not support interactive command-line management sessions.
SNMPv1 is used for network monitoring, not secure CLI access, and lacks encryption. Candidates must recognize that only SSH encrypts the session, making it the secure and preferred protocol for remote management in Cisco environments.
Why the other options are wrong
FTP is designed for transferring files between devices and does not provide an interactive command-line interface for remote device management. It also lacks encryption for session data, making it unsuitable for secure remote CLI access.
TFTP is a simple file transfer protocol used mainly for transferring configuration files or IOS images. It does not support interactive remote CLI sessions and lacks encryption, so it cannot replace Telnet for secure management.
SNMPv1 is a protocol used for network monitoring and management but does not provide an interactive CLI interface. It also lacks encryption, making it unsuitable for secure remote management sessions.