exam questions

Exam 300-135 All Questions

View all questions & answers for the 300-135 exam

Exam 300-135 topic 7 question 35 discussion

Actual exam question from Cisco's 300-135
Question #: 35
Topic #: 7
[All 300-135 Questions]

Which command securely encrypts the enable password on an IOS device?

  • A. enable secret
  • B. enable secure
  • C. service password-encryption
  • D. enable password
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
oxelbashir
5 years, 2 months ago
A is the correct answer service password-encryption is encrypt all password appear on the configuration using type 7. The question specifically ask about enable password only
upvoted 1 times
...
MunirAbeid
5 years, 2 months ago
The best way I like to remember it is: Enable Secret: hashes your enable password so that even if someone has access to the configuration and could copy / paste the code into a Cisco Password Cracker they still wouldn't be able to figure out what the correct password is. Service password-encryption: This is used for encrypting all your passwords so that they cannot be easily read by people watching you configure the switch over your shoulder. It is a lot better having the passwords not show clear text as then other people who don't need to be accessing the switch still do not know. Now, you don't want to be passing around your configs to everyone because if they get the config and copy / paste the password, even with service password-encryption enabled, it will be easily crackable in many websites. The only secure way is using enable secret. So correct answer is A.
upvoted 1 times
...
MunirAbeid
5 years, 2 months ago
enable secret: only enable pass encrypted service password-encryption: all password on a device is encrypted (vty, con....)
upvoted 1 times
...
MunirAbeid
5 years, 2 months ago
Correct answer is C
upvoted 1 times
...
works
5 years, 2 months ago
This is a very poorly worded question. The enable password is different than the enable secret – in fact it is possible to have both of them present on a device at the same time (if they are both present the enable secret takes precedence). I feel like the answer is C as it involves encrypting the enable PASSWORD (even though it is a less secure encryption than would be used on the enable SECRET).
upvoted 1 times
...
wjavier
5 years, 2 months ago
C service password-encryption -> Encrypt passwords. To specify an additional layer of security over the enable password command, use the enable secret command. https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/security/d1/sec-d1-cr-book/sec-cr-e1.html#wp3438133060
upvoted 2 times
...
tio1
5 years, 6 months ago
Correct answer is C. The question does not state how securely in the way of comparison, so in regard of the question both md5 and type 7 (vigerene if i remember correctly) are both secure enough. Enable secret produces a hash from a seed, it does not encrypt. Hence the question does ask to securely which command securely encrypts the enable password, thus C is correct
upvoted 3 times
pen08
5 years, 4 months ago
A is correct. enable password can be easily decrypted compared to enable secret.
upvoted 4 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago