Courseiva
mediumMultiple SelectObjective-mapped

300-410 Practice Question: Which TWO statements about the Cisco IOS-XE SSH…

Which TWO statements about the Cisco IOS-XE SSH server configuration are true? (Choose TWO.)

⚠ Common exam trap

Cisco often tests the misconception that SSH must be explicitly enabled with a version command, when in fact SSH version 2 is the default and is automatically activated upon RSA key generation, and that 'transport input ssh' is a VTY-line command, not a global one.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The hostname and domain name must be configured before generating RSA keys.

Cisco IOS-XE requires both a hostname and a domain name to be configured before generating RSA keys. The RSA key generation process uses the fully qualified domain name (FQDN) as part of the key label, and without these values, the 'crypto key generate rsa' command will fail or prompt for missing parameters.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The hostname and domain name must be configured before generating RSA keys.

    Why this is correct

    RSA keys require a fully qualified domain name (FQDN) which uses both hostname and domain name.

  • SSH version 2 is the default and is automatically enabled when RSA keys are generated.

    Why this is correct

    Cisco IOS-XE defaults to SSH version 2 when RSA keys are generated.

  • The command 'ip ssh version 1' is required to enable SSH.

    Why it's wrong here

    SSH version 2 is default; version 1 is deprecated and not recommended.

  • The command 'transport input ssh' must be configured globally.

    Why it's wrong here

    This command is applied under the VTY line configuration, not globally.

  • RSA key modulus size must be at least 2048 bits for SSH version 2.

    Why it's wrong here

    While 2048 bits is recommended, SSH version 2 works with smaller modulus sizes as well.

Quick reference

Asymmetric Encryption Algorithm Comparison

AlgorithmKey ExchangeSignaturesEquivalent Security KeyNotes
RSA-3072YesYes128-bitWidely deployed; slow for bulk data
ECDSA P-256NoYes128-bitFast signatures; standard TLS certs
ECDH / ECDHEYesNo128-bitPerfect forward secrecy in TLS 1.3
DH / DHEYesNo128-bit (3072-bit key)Replaced by ECDHE in modern TLS
Ed25519NoYes~128-bitSSH keys, modern PKI

About these practice questions

One of 1,966 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.