350-401 Architecture Practice Question
A network engineer is configuring a new Cisco IOS router and needs to ensure that the router can be managed remotely via SSH. The engineer has already generated RSA keys and configured a username and password. Which additional command is required to enable SSH access on the VTY lines?
⚠ Common exam trap
The trap here is thinking that generating RSA keys or setting SSH version 2 automatically enables SSH on the VTY lines, when in fact the 'transport input ssh' command is specifically required to allow SSH connections.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
transport input ssh
To enable SSH access on a Cisco IOS router, after generating RSA keys and configuring local authentication, the VTY lines must be configured with 'transport input ssh'. This command restricts incoming connections to SSH, ensuring secure remote management. The other commands are either prerequisites already completed or additional security settings that do not directly enable SSH on the VTY lines.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
ip ssh version 2
Why it's wrong here
'ip ssh version 2' configures the router to use SSH version 2, which is more secure than version 1. While it is a good practice, it does not enable SSH access on the VTY lines. The VTY lines must still be configured with 'transport input ssh' to accept SSH connections. This command alone does not fulfill the requirement.
- ✗
login local
Why it's wrong here
'login local' is used to authenticate users against the local username database, but it does not enable SSH specifically. It is often used in conjunction with SSH configuration, but it does not restrict the VTY lines to SSH. Without 'transport input ssh', the VTY lines might still accept Telnet, so this command alone does not meet the requirement.
- ✓
transport input ssh
Why this is correct
The command 'transport input ssh' under the VTY line configuration restricts incoming connections to SSH only, which is required to enable SSH access. Without it, the router may still allow Telnet or other protocols. This command ensures that only secure shell connections are accepted, aligning with the requirement to manage the router via SSH.
- ✗
crypto key generate rsa
Why it's wrong here
The 'crypto key generate rsa' command is used to generate RSA keys, which are necessary for SSH. However, the scenario states that RSA keys have already been generated. Therefore, this command is not needed again. It does not enable SSH on the VTY lines; it only creates the keys used for encryption.
Quick reference
Asymmetric Encryption Algorithm Comparison
| Algorithm | Key Exchange | Signatures | Equivalent Security Key | Notes |
|---|---|---|---|---|
| RSA-3072 | Yes | Yes | 128-bit | Widely deployed; slow for bulk data |
| ECDSA P-256 | No | Yes | 128-bit | Fast signatures; standard TLS certs |
| ECDH / ECDHE | Yes | No | 128-bit | Perfect forward secrecy in TLS 1.3 |
| DH / DHE | Yes | No | 128-bit (3072-bit key) | Replaced by ECDHE in modern TLS |
| Ed25519 | No | Yes | ~128-bit | SSH keys, modern PKI |
Go deeper
Related to this question
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.