Courseiva
Security →mediumMultiple Choice

CCNP Security Practice Question

An engineer is configuring a Cisco IOS XE switch to secure the management plane. The requirement is to allow SSH only from the management subnet 10.10.10.0/24 and block all other management protocols such as Telnet and HTTP. Which configuration approach best meets this requirement?

⚠ Common exam trap

The trap here is assuming that disabling HTTP and Telnet on the web server alone secures management access, when VTY line transport and access-class controls are what actually restrict SSH sources.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Apply an ACL to the VTY lines with transport input ssh and configure the ACL to permit 10.10.10.0/24 only.

The VTY lines control remote management access. Setting transport input ssh disables Telnet and other line protocols, while an access-class ACL applied to the VTY lines filters source addresses before login. Permitting only 10.10.10.0/24 satisfies the subnet restriction. Together these settings secure the management plane by limiting both the protocol and the source of administrative connections.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure an ACL on the management VLAN SVI to deny Telnet and HTTP, and rely on the default transport input all on the VTY lines.

    Why it's wrong here

    Filtering at the SVI affects all traffic in the management VLAN, including legitimate services, and does not directly control which protocols the VTY lines accept. Leaving transport input at its default of all allows Telnet and other protocols unless the ACL is perfect. This approach is broader than necessary and does not enforce SSH-only access to the device.

  • ✗

    Enable AAA with a local database and configure privilege levels so that only users from 10.10.10.0/24 can log in.

    Why it's wrong here

    AAA authenticates users but does not restrict source subnets or disable Telnet and HTTP. Privilege levels control what commands an authenticated user can run, not where the connection originates. An attacker from another subnet could still reach the VTY lines and attempt login, so this does not meet the requirement to allow SSH only from the management subnet.

  • ✓

    Apply an ACL to the VTY lines with transport input ssh and configure the ACL to permit 10.10.10.0/24 only.

    Why this is correct

    Combining transport input ssh on the VTY lines with an access-class ACL that permits only 10.10.10.0/24 restricts remote management to SSH from the management subnet. Telnet and other line-based protocols are refused because transport input is limited to ssh, and non-permitted source addresses are dropped by the ACL before they reach the VTY lines, satisfying both requirements.

  • ✗

    Configure ip http secure-server, disable ip http server, and apply an ACL to the VTY lines that permits any source using SSH.

    Why it's wrong here

    Disabling HTTP and enabling HTTPS secures the web interface but does not address SSH source restrictions or Telnet. An ACL that permits any source on SSH fails the requirement to limit management access to 10.10.10.0/24. This option only partially addresses the management plane hardening and leaves remote SSH open to the entire network.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.