300-410 Infrastructure Security Practice Question
A network technician is configuring a Cisco IOS router to use SSH for remote management. The technician generates an RSA key pair with 2048 bits, configures a local username and password, and enables SSH version 2. However, when attempting to connect via SSH, the connection is refused. Which additional configuration is required on the VTY lines to allow SSH access?
⚠ Common exam trap
The trap here is assuming that generating RSA keys and enabling SSH version 2 automatically enables SSH on the VTY lines; you must explicitly allow SSH transport.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
transport input ssh
To enable SSH on a Cisco IOS router, you must generate an RSA key pair, configure a local username and password, enable SSH version 2, and apply 'transport input ssh' on the VTY lines. Without this transport command, the router may not accept SSH connections, resulting in a refused connection. The other options either enable insecure protocols or do not address the transport mechanism.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
login local
Why it's wrong here
The 'login local' command tells the router to use the local username database for authentication. While this is necessary for local authentication, it does not enable the SSH protocol on the VTY lines. Without 'transport input ssh', the router will not accept SSH connections even if authentication is configured. Thus, this command alone does not resolve the connection refused issue.
- ✗
transport input all
Why it's wrong here
The 'transport input all' command allows both Telnet and SSH on the VTY lines. While this would permit SSH, it also enables Telnet, which is insecure and not the best practice. The requirement is to allow SSH access, but the connection is refused likely because no transport input is configured, and the default may be none in some IOS versions. However, 'transport input all' is not the most secure or specific answer.
- ✓
transport input ssh
Why this is correct
The 'transport input ssh' command on the VTY lines restricts incoming connections to SSH only, which is the secure method. If no transport input is configured, the router may not accept any remote connections, causing the SSH connection to be refused. This command explicitly enables SSH and disables Telnet, satisfying the requirement.
- ✗
exec-timeout 0 0
Why it's wrong here
The 'exec-timeout 0 0' command disables the idle timeout for console and VTY sessions, preventing automatic logout. This does not affect the ability to establish an SSH connection. The connection is refused because SSH is not enabled on the VTY lines, not because of a timeout setting. Therefore, this command is irrelevant to the problem.
Quick reference
Asymmetric Encryption Algorithm Comparison
| Algorithm | Key Exchange | Signatures | Equivalent Security Key | Notes |
|---|---|---|---|---|
| RSA-3072 | Yes | Yes | 128-bit | Widely deployed; slow for bulk data |
| ECDSA P-256 | No | Yes | 128-bit | Fast signatures; standard TLS certs |
| ECDH / ECDHE | Yes | No | 128-bit | Perfect forward secrecy in TLS 1.3 |
| DH / DHE | Yes | No | 128-bit (3072-bit key) | Replaced by ECDHE in modern TLS |
| Ed25519 | No | Yes | ~128-bit | SSH keys, modern PKI |
Go deeper
Related to this question
About these practice questions
One of 1,401 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.