Courseiva
Architecture →easyMultiple Choice

350-401 Architecture Practice Question

A network engineer is configuring a new Cisco IOS router and needs to ensure that the router can be managed remotely via SSH. The engineer has already generated RSA keys and configured a username and password. Which additional command is required to enable SSH access on the VTY lines?

⚠ Common exam trap

The trap here is thinking that generating RSA keys or setting SSH version 2 automatically enables SSH on the VTY lines, when in fact the 'transport input ssh' command is specifically required to allow SSH connections.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

transport input ssh

To enable SSH access on a Cisco IOS router, after generating RSA keys and configuring local authentication, the VTY lines must be configured with 'transport input ssh'. This command restricts incoming connections to SSH, ensuring secure remote management. The other commands are either prerequisites already completed or additional security settings that do not directly enable SSH on the VTY lines.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    ip ssh version 2

    Why it's wrong here

    'ip ssh version 2' configures the router to use SSH version 2, which is more secure than version 1. While it is a good practice, it does not enable SSH access on the VTY lines. The VTY lines must still be configured with 'transport input ssh' to accept SSH connections. This command alone does not fulfill the requirement.

  • ✗

    login local

    Why it's wrong here

    'login local' is used to authenticate users against the local username database, but it does not enable SSH specifically. It is often used in conjunction with SSH configuration, but it does not restrict the VTY lines to SSH. Without 'transport input ssh', the VTY lines might still accept Telnet, so this command alone does not meet the requirement.

  • ✓

    transport input ssh

    Why this is correct

    The command 'transport input ssh' under the VTY line configuration restricts incoming connections to SSH only, which is required to enable SSH access. Without it, the router may still allow Telnet or other protocols. This command ensures that only secure shell connections are accepted, aligning with the requirement to manage the router via SSH.

  • ✗

    crypto key generate rsa

    Why it's wrong here

    The 'crypto key generate rsa' command is used to generate RSA keys, which are necessary for SSH. However, the scenario states that RSA keys have already been generated. Therefore, this command is not needed again. It does not enable SSH on the VTY lines; it only creates the keys used for encryption.

Quick reference

Asymmetric Encryption Algorithm Comparison

AlgorithmKey ExchangeSignaturesEquivalent Security KeyNotes
RSA-3072YesYes128-bitWidely deployed; slow for bulk data
ECDSA P-256NoYes128-bitFast signatures; standard TLS certs
ECDH / ECDHEYesNo128-bitPerfect forward secrecy in TLS 1.3
DH / DHEYesNo128-bit (3072-bit key)Replaced by ECDHE in modern TLS
Ed25519NoYes~128-bitSSH keys, modern PKI

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.