CCNP Security Practice Question
A network administrator must secure management access to a Cisco IOS XE router so that only SSH version 2 is accepted and Telnet is disabled on all VTY lines. Which configuration accomplishes this requirement?
⚠ Common exam trap
Many exam-takers confuse transport input with transport output; only transport input controls which protocols may connect inbound to the VTY lines.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure transport input ssh on the VTY lines and set the SSH version to 2 globally.
Restricting management to SSH requires the transport input ssh command applied to the VTY lines, which removes Telnet as an accepted transport. Enforcing SSH version 2 with ip ssh version 2 ensures the stronger protocol is used. Together they block Telnet and guarantee only SSHv2 sessions are accepted on the router.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure line vty 0 4 with the exec-timeout command and set the SSH version to 2.
Why it's wrong here
The exec-timeout command disconnects idle sessions after a specified period, improving session hygiene but not restricting the protocol used for management access. Telnet remains enabled on the VTY lines, so the requirement to accept only SSH version 2 and disable Telnet is not satisfied by this configuration.
- ✓
Configure transport input ssh on the VTY lines and set the SSH version to 2 globally.
Why this is correct
The transport input ssh command on the VTY lines restricts inbound management sessions to SSH, effectively disabling Telnet. Setting the SSH version to 2 with ip ssh version 2 ensures only the stronger protocol version is negotiated. Together these commands satisfy the requirement to allow only SSHv2 and block Telnet.
- ✗
Configure transport input telnet ssh on the VTY lines and set the SSH version to 2.
Why it's wrong here
Including telnet in the transport input list explicitly permits Telnet sessions on the VTY lines, which directly violates the requirement to disable Telnet. Even though SSH version 2 is enforced, the presence of telnet as an allowed transport leaves an insecure management path open and fails the stated security policy.
- ✗
Configure transport output ssh on the VTY lines and set the SSH version to 2.
Why it's wrong here
The transport output command controls which protocols the router may use for outgoing sessions initiated from the device, not inbound management access to the VTY lines. It does not restrict how administrators connect to the router, so Telnet remains available for inbound sessions and the requirement is not met.
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.