easyMultiple Choice
ISC2 CC Practice Question: Protocols provides secure remote administration…
Which of the following protocols provides secure remote administration of a network device over an untrusted network?
⚠ Common exam trap
ISC2 often tests the distinction between 'secure' and 'insecure' protocols, and the trap here is that candidates may confuse Telnet with SSH because both provide remote CLI access, forgetting that Telnet lacks encryption entirely.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
SSH
SSH (Secure Shell) is correct because it encrypts all traffic, including authentication credentials and commands, using strong cryptographic algorithms, making it safe for remote administration over untrusted networks. It operates on TCP port 22 and provides confidentiality, integrity, and authentication, unlike cleartext protocols. SSH is the standard for secure CLI access to network devices such as routers and switches.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
SNMPv1
Why it's wrong here
SNMPv1 transmits community strings in cleartext, so credentials crossing an untrusted network are readable by anyone capturing traffic. It is tempting because SNMP does serve network device administration, but for monitoring and configuration polling on trusted management networks. Secure remote administration requires an encrypted channel such as SSH, which SNMPv1 cannot provide.
- ✗
Telnet
Why it's wrong here
Telnet transmits credentials and session data in cleartext, so an eavesdropper on an untrusted network captures them directly. SSH provides the encrypted remote administration the scenario demands. Telnet remains usable for trusted, isolated lab segments where confidentiality is not a requirement.
- ✗
HTTP
Why it's wrong here
HTTP carries web content unencrypted and provides no interactive device-administration session; it cannot securely manage a router or switch. HTTPS with a management interface, or SSH, supplies the encryption required. HTTP is the right answer when serving public web pages that need no confidentiality.
- ✓
SSH
Why this is correct
SSH encrypts the entire session, including authentication credentials and commands, using strong ciphers over TCP port 22. This satisfies the stem's untrusted-network constraint, unlike Telnet, which transmits everything in cleartext. It also supports key-based authentication and tunnelling, making it the standard for secure remote administration of network devices.
Go deeper
Related to this question
Learn chapter
Network Security Components and Controls
Key term
TCP
TCP is a connection-oriented transport layer protocol that ensures reliable, ordered, and error-checked delivery of data between applications over IP networks.
Key term
Authentication
Authentication is the process of verifying that someone or something is who or what it claims to be before granting access to a system or resource.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.