CCNP Security Practice Question
An engineer is configuring a Cisco IOS XE switch to secure the management plane. The requirement is to allow SSH only from the management subnet 10.10.10.0/24 and block all other management protocols such as Telnet and HTTP. Which configuration approach best meets this requirement?
⚠ Common exam trap
The trap here is assuming that disabling HTTP and Telnet on the web server alone secures management access, when VTY line transport and access-class controls are what actually restrict SSH sources.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Apply an ACL to the VTY lines with transport input ssh and configure the ACL to permit 10.10.10.0/24 only.
The VTY lines control remote management access. Setting transport input ssh disables Telnet and other line protocols, while an access-class ACL applied to the VTY lines filters source addresses before login. Permitting only 10.10.10.0/24 satisfies the subnet restriction. Together these settings secure the management plane by limiting both the protocol and the source of administrative connections.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure an ACL on the management VLAN SVI to deny Telnet and HTTP, and rely on the default transport input all on the VTY lines.
Why it's wrong here
Filtering at the SVI affects all traffic in the management VLAN, including legitimate services, and does not directly control which protocols the VTY lines accept. Leaving transport input at its default of all allows Telnet and other protocols unless the ACL is perfect. This approach is broader than necessary and does not enforce SSH-only access to the device.
- ✗
Enable AAA with a local database and configure privilege levels so that only users from 10.10.10.0/24 can log in.
Why it's wrong here
AAA authenticates users but does not restrict source subnets or disable Telnet and HTTP. Privilege levels control what commands an authenticated user can run, not where the connection originates. An attacker from another subnet could still reach the VTY lines and attempt login, so this does not meet the requirement to allow SSH only from the management subnet.
- ✓
Apply an ACL to the VTY lines with transport input ssh and configure the ACL to permit 10.10.10.0/24 only.
Why this is correct
Combining transport input ssh on the VTY lines with an access-class ACL that permits only 10.10.10.0/24 restricts remote management to SSH from the management subnet. Telnet and other line-based protocols are refused because transport input is limited to ssh, and non-permitted source addresses are dropped by the ACL before they reach the VTY lines, satisfying both requirements.
- ✗
Configure ip http secure-server, disable ip http server, and apply an ACL to the VTY lines that permits any source using SSH.
Why it's wrong here
Disabling HTTP and enabling HTTPS secures the web interface but does not address SSH source restrictions or Telnet. An ACL that permits any source on SSH fails the requirement to limit management access to 10.10.10.0/24. This option only partially addresses the management plane hardening and leaves remote SSH open to the entire network.
Visual reference
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.