ISC2 CC Network Security Practice Question
Which of the following is a security concern associated with the Telnet protocol?
⚠ Common exam trap
CC often tests protocol security; candidates might confuse Telnet with protocols that use weak encryption, but Telnet uses no encryption at all, making 'cleartext' the correct concern.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It transmits data in cleartext.
Telnet transmits all data, including usernames and passwords, in cleartext, making it vulnerable to eavesdropping and credential theft. This lack of encryption is the primary security concern associated with Telnet. Other options do not accurately describe Telnet's security weaknesses.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
It transmits data in cleartext.
Why this is correct
Telnet sends all session data, including credentials and commands, as unencrypted cleartext across the network. Anyone capturing traffic on the path can read or alter it, which is the fundamental security weakness distinguishing Telnet from SSH.
- ✗
It requires certificate management.
Why it's wrong here
Telnet performs no certificate exchange or PKI validation at all, so certificate management is irrelevant to it; the real exposure is cleartext transmission of credentials. It tempts because certificate lifecycle handling is a genuine operational burden for TLS-based remote access tools such as SSH or RDP with TLS.
- ✗
It is vulnerable to DNS poisoning.
Why it's wrong here
Telnet's security concern is that it transmits credentials and session data in cleartext, exposing them to interception. DNS poisoning attacks name resolution and affects any protocol, so it is not specific to Telnet. Cleartext transmission is the actual weakness, which is why SSH replaced Telnet for remote administration.
- ✗
It uses encryption that is too weak.
Why it's wrong here
Telnet applies no encryption whatsoever, so describing its cipher as merely weak misstates the flaw; credentials and commands cross the wire in cleartext. It tempts because weak-cipher concerns genuinely apply to legacy protocols such as SSLv3 or WEP, where encryption exists but is breakable.
Go deeper
Related to this question
Key term
Encryption
Encryption is the process of converting readable data into a secret code to prevent unauthorized access.
Key term
Telnet
Telnet is a network protocol that provides a bidirectional, interactive text-based communication session between two machines over a network, typically used for remote access and management of network devices.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.