Courseiva
easyMultiple Choice

ISC2 CC Practice Question: Protocols provides secure remote administration…

Which of the following protocols provides secure remote administration of a network device over an untrusted network?

⚠ Common exam trap

ISC2 often tests the distinction between 'secure' and 'insecure' protocols, and the trap here is that candidates may confuse Telnet with SSH because both provide remote CLI access, forgetting that Telnet lacks encryption entirely.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SSH

SSH (Secure Shell) is correct because it encrypts all traffic, including authentication credentials and commands, using strong cryptographic algorithms, making it safe for remote administration over untrusted networks. It operates on TCP port 22 and provides confidentiality, integrity, and authentication, unlike cleartext protocols. SSH is the standard for secure CLI access to network devices such as routers and switches.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    SNMPv1

    Why it's wrong here

    SNMPv1 transmits community strings in cleartext, so credentials crossing an untrusted network are readable by anyone capturing traffic. It is tempting because SNMP does serve network device administration, but for monitoring and configuration polling on trusted management networks. Secure remote administration requires an encrypted channel such as SSH, which SNMPv1 cannot provide.

  • ✗

    Telnet

    Why it's wrong here

    Telnet transmits credentials and session data in cleartext, so an eavesdropper on an untrusted network captures them directly. SSH provides the encrypted remote administration the scenario demands. Telnet remains usable for trusted, isolated lab segments where confidentiality is not a requirement.

  • ✗

    HTTP

    Why it's wrong here

    HTTP carries web content unencrypted and provides no interactive device-administration session; it cannot securely manage a router or switch. HTTPS with a management interface, or SSH, supplies the encryption required. HTTP is the right answer when serving public web pages that need no confidentiality.

  • ✓

    SSH

    Why this is correct

    SSH encrypts the entire session, including authentication credentials and commands, using strong ciphers over TCP port 22. This satisfies the stem's untrusted-network constraint, unlike Telnet, which transmits everything in cleartext. It also supports key-based authentication and tunnelling, making it the standard for secure remote administration of network devices.

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.