Courseiva
Security →easyMultiple Choice

350-401 Security Practice Question

A network administrator needs to secure management access to a Cisco IOS XE switch. The requirement is that only SSH version 2 with a 2048-bit RSA key be accepted, that Telnet be disabled, and that only the 'netadmin' user with privilege level 15 be allowed to log in via VTY lines 0 through 4. Which configuration accomplishes this?

⚠ Common exam trap

The trap here is overlooking one of the three simultaneous conditions—key size, SSH version, or privilege level—and selecting a configuration that only partially satisfies the policy.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

crypto key generate rsa modulus 2048; ip ssh version 2; line vty 0 4; transport input ssh; login local; username netadmin privilege 15 secret <password>

The correct configuration generates a 2048-bit RSA key, forces SSH version 2, restricts VTY transport to SSH only (disabling Telnet), and uses local authentication with the netadmin user at privilege 15. Alternatives fail because they use a weak key size, allow Telnet, force SSHv1, or assign the wrong privilege level, each violating at least one stated requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    crypto key generate rsa modulus 2048; ip ssh version 2; line vty 0 4; transport input ssh; login local; username netadmin privilege 15 secret <password>

    Why this is correct

    This sequence generates a 2048-bit RSA key, restricts SSH to version 2, disables Telnet by allowing only SSH transport on the VTY lines, and enforces local authentication with a privilege 15 user. All three requirements—SSHv2, no Telnet, and netadmin-only access—are satisfied by this configuration.

  • ✗

    crypto key generate rsa modulus 2048; ip ssh version 1; line vty 0 4; transport input ssh; login local; username netadmin privilege 15 secret <password>

    Why it's wrong here

    The RSA key size and Telnet restriction are correct, but forcing SSH version 1 violates the requirement to accept only SSH version 2. SSHv1 has known weaknesses, so this configuration is not acceptable even though the other parameters appear correct.

  • ✗

    crypto key generate rsa modulus 2048; ip ssh version 2; line vty 0 4; transport input ssh; login local; username netadmin privilege 1 secret <password>

    Why it's wrong here

    This configuration satisfies SSHv2, disables Telnet, and restricts to SSH transport, but assigns the netadmin user privilege level 1 instead of 15. The requirement explicitly states privilege level 15, so the user would lack the necessary administrative rights and the configuration fails the stated policy.

  • ✗

    crypto key generate rsa modulus 1024; ip ssh version 2; line vty 0 4; transport input telnet ssh; login local; username netadmin privilege 15 secret <password>

    Why it's wrong here

    The 1024-bit modulus does not meet the 2048-bit key requirement, and allowing both Telnet and SSH violates the requirement to disable Telnet. Although SSHv2 and the local user are configured, two of the three stated conditions are unmet, so this configuration is incorrect.

Quick reference

Asymmetric Encryption Algorithm Comparison

AlgorithmKey ExchangeSignaturesEquivalent Security KeyNotes
RSA-3072YesYes128-bitWidely deployed; slow for bulk data
ECDSA P-256NoYes128-bitFast signatures; standard TLS certs
ECDH / ECDHEYesNo128-bitPerfect forward secrecy in TLS 1.3
DH / DHEYesNo128-bit (3072-bit key)Replaced by ECDHE in modern TLS
Ed25519NoYes~128-bitSSH keys, modern PKI

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.