Cisco CCNA 200-301 Device Access and Authentication Practice Test
Topic 34 focuses on Device Access, Passwords and Authentication Methods for the Cisco Certified Network Associate (CCNA) certification and the 200-301 exam, using Cisco networking and Cisco IOS concepts where relevant. For broader exam preparation, review the Cisco CCNA 200-301 Exam Dumps page. Each question includes a concise explanation of the correct answer and the technical reason the other choices are incorrect.
Question 1
Which Cisco IOS command configures a hashed privileged EXEC password?
Correct Answer: B
Correct Answer
Answer B is correct because the selected answer describes a Cisco IOS command that configures a hashed privileged EXEC password.
Incorrect Answers
Answer A is incorrect because the “Password complexity” option describes a different concept: a policy requirement that increases resistance to guessing by requiring sufficient length and character diversity.
Answer C is incorrect because the “service password-encryption” option describes a different concept: a Cisco IOS feature that obfuscates certain plaintext passwords in the configuration, but is not a strong password-hashing mechanism.
Answer D is incorrect because the “Privilege level” option describes a different concept: an IOS mechanism that controls which commands an authenticated user can execute.
Question 2
Which account contains a username and credential stored directly on a network device?
Correct Answer: D
Correct Answer
Answer D is correct because the selected answer describes a username and credential stored directly on a network device for authentication.
Incorrect Answers
Answer A is incorrect because the “SSH public-key authentication” option describes a different concept: an authentication method that proves possession of a private key instead of relying only on a typed password.
Answer B is incorrect because the “Privilege level” option describes a different concept: an IOS mechanism that controls which commands an authenticated user can execute.
Answer C is incorrect because the “Biometric authentication” option describes a different concept: Authentication based on a physical or behavioral characteristic of a person.
Question 3
Which Cisco IOS feature obfuscates certain plaintext passwords in the configuration, but is not a strong password-hashing mechanism?
Correct Answer: B
Correct Answer
Answer B is correct because the selected answer describes a Cisco IOS feature that obfuscates certain plaintext passwords in the configuration, but is not a strong password-hashing mechanism.
Incorrect Answers
Answer A is incorrect because the “Multifactor authentication” option describes a different concept: Authentication that requires evidence from two or more different factor categories.
Answer C is incorrect because the “Privilege level” option describes a different concept: an IOS mechanism that controls which commands an authenticated user can execute.
Answer D is incorrect because the “Password complexity” option describes a different concept: a policy requirement that increases resistance to guessing by requiring sufficient length and character diversity.
Question 4
Which policy requirement increases resistance to guessing by requiring sufficient length and character diversity?
Correct Answer: D
Correct Answer
Answer D is correct because the selected answer describes a policy requirement that increases resistance to guessing by requiring sufficient length and character diversity.
Incorrect Answers
Answer A is incorrect because the “SSH public-key authentication” option describes a different concept: an authentication method that proves possession of a private key instead of relying only on a typed password.
Answer B is incorrect because the “enable secret” option describes a different concept: a Cisco IOS command that configures a hashed privileged EXEC password.
Answer C is incorrect because the “service password-encryption” option describes a different concept: a Cisco IOS feature that obfuscates certain plaintext passwords in the configuration, but is not a strong password-hashing mechanism.
Question 5
Which term describes authentication that requires evidence from two or more different factor categories?
Correct Answer: B
Correct Answer
Answer B is correct because Authentication that requires evidence from two or more different factor categories.
Incorrect Answers
Answer A is incorrect because the “Local user account” option describes a different concept: a username and credential stored directly on a network device for authentication.
Answer C is incorrect because the “service password-encryption” option describes a different concept: a Cisco IOS feature that obfuscates certain plaintext passwords in the configuration, but is not a strong password-hashing mechanism.
Answer D is incorrect because the “Local authentication” option describes a different concept: Authentication performed by checking credentials stored on the device itself rather than a central AAA server.
Question 6
Which signed electronic credential binds an identity to a public key?
Correct Answer: C
Correct Answer
Answer C is correct because the selected answer describes a signed electronic credential that binds an identity to a public key.
Incorrect Answers
Answer A is incorrect because the “enable secret” option describes a different concept: a Cisco IOS command that configures a hashed privileged EXEC password.
Answer B is incorrect because the “SSH public-key authentication” option describes a different concept: an authentication method that proves possession of a private key instead of relying only on a typed password.
Answer D is incorrect because the “Local user account” option describes a different concept: a username and credential stored directly on a network device for authentication.
Question 7
Which term describes authentication based on a physical or behavioral characteristic of a person?
Correct Answer: A
Correct Answer
Answer A is correct because it describes authentication based on a physical or behavioral characteristic of a person.
Incorrect Answers
Answer B is incorrect because the “service password-encryption” option describes a different concept: a Cisco IOS feature that obfuscates certain plaintext passwords in the configuration, but is not a strong password-hashing mechanism.
Answer C is incorrect because the “Local authentication” option describes a different concept: Authentication performed by checking credentials stored on the device itself rather than a central AAA server.
Answer D is incorrect because the “Privilege level” option describes a different concept: an IOS mechanism that controls which commands an authenticated user can execute.
Question 8
Which authentication method proves possession of a private key instead of relying only on a typed password?
Correct Answer: A
Correct Answer
Answer A is correct because the selected answer describes an authentication method that proves possession of a private key instead of relying only on a typed password.
Incorrect Answers
Answer B is incorrect because the “Multifactor authentication” option describes a different concept: Authentication that requires evidence from two or more different factor categories.
Answer C is incorrect because the “service password-encryption” option describes a different concept: a Cisco IOS feature that obfuscates certain plaintext passwords in the configuration, but is not a strong password-hashing mechanism.
Answer D is incorrect because the “Biometric authentication” option describes a different concept: Authentication based on a physical or behavioral characteristic of a person.
Question 9
Which IOS mechanism controls which commands an authenticated user can execute?
Correct Answer: B
Correct Answer
Answer B is correct because the selected answer describes an IOS mechanism that controls which commands an authenticated user can execute.
Incorrect Answers
Answer A is incorrect because the “Local user account” option describes a different concept: a username and credential stored directly on a network device for authentication.
Answer C is incorrect because the “Multifactor authentication” option describes a different concept: Authentication that requires evidence from two or more different factor categories.
Answer D is incorrect because the “service password-encryption” option describes a different concept: a Cisco IOS feature that obfuscates certain plaintext passwords in the configuration, but is not a strong password-hashing mechanism.
Question 10
Which term describes authentication performed by checking credentials stored on the device itself rather than a central AAA server?
Correct Answer: B
Correct Answer
Answer B is correct because it describes authentication performed by checking credentials stored on the device itself rather than a central AAA server.
Incorrect Answers
Answer A is incorrect because the “service password-encryption” option describes a different concept: a Cisco IOS feature that obfuscates certain plaintext passwords in the configuration, but is not a strong password-hashing mechanism.
Answer C is incorrect because the “Biometric authentication” option describes a different concept: Authentication based on a physical or behavioral characteristic of a person.
Answer D is incorrect because the “Digital certificate” option describes a different concept: a signed electronic credential that binds an identity to a public key.
Question 11
For enable secret, which statement is accurate?
Correct Answer: B
Correct Answer
Answer B is correct because the choice accurately describes enable secret: A Cisco IOS command that configures a hashed privileged EXEC password.
Incorrect Answers
Answer A is incorrect because the “Biometric authentication” option describes a different concept: Authentication based on a physical or behavioral characteristic of a person.
Answer C is incorrect because the “Local user account” option describes a different concept: a username and credential stored directly on a network device for authentication.
Answer D is incorrect because the “service password-encryption” option describes a different concept: a Cisco IOS feature that obfuscates certain plaintext passwords in the configuration, but is not a strong password-hashing mechanism.
Question 12
For Local user account, which statement is accurate?
Correct Answer: D
Correct Answer
Answer D is correct because the selected answer describes a username and credential stored directly on a network device for authentication.
Incorrect Answers
Answer A is incorrect because the “Local authentication” option describes a different concept: Authentication performed by checking credentials stored on the device itself rather than a central AAA server.
Answer B is incorrect because the “Biometric authentication” option describes a different concept: Authentication based on a physical or behavioral characteristic of a person.
Answer C is incorrect because the “enable secret” option describes a different concept: a Cisco IOS command that configures a hashed privileged EXEC password.
Question 13
For service password-encryption, which statement is accurate?
Correct Answer: A
Correct Answer
Answer A is correct because the selected answer describes a Cisco IOS feature that obfuscates certain plaintext passwords in the configuration, but is not a strong password-hashing mechanism.
Incorrect Answers
Answer B is incorrect because the “enable secret” option describes a different concept: a Cisco IOS command that configures a hashed privileged EXEC password.
Answer C is incorrect because the “Password complexity” option describes a different concept: a policy requirement that increases resistance to guessing by requiring sufficient length and character diversity.
Answer D is incorrect because the “Privilege level” option describes a different concept: an IOS mechanism that controls which commands an authenticated user can execute.
Question 14
For Password complexity, which statement is accurate?
Correct Answer: D
Correct Answer
Answer D is correct because it accurately defines Password complexity. The matching definition is: A policy requirement that increases resistance to guessing by requiring sufficient length and character diversity.
Incorrect Answers
Answer A is incorrect because the “Local user account” option describes a different concept: a username and credential stored directly on a network device for authentication.
Answer B is incorrect because the “enable secret” option describes a different concept: a Cisco IOS command that configures a hashed privileged EXEC password.
Answer C is incorrect because the “SSH public-key authentication” option describes a different concept: an authentication method that proves possession of a private key instead of relying only on a typed password.
Question 15
For Multifactor authentication, which statement is accurate?
Correct Answer: D
Correct Answer
Answer D is correct because the choice accurately describes Multifactor authentication: Authentication that requires evidence from two or more different factor categories.
Incorrect Answers
Answer A is incorrect because the “SSH public-key authentication” option describes a different concept: an authentication method that proves possession of a private key instead of relying only on a typed password.
Answer B is incorrect because the “Biometric authentication” option describes a different concept: Authentication based on a physical or behavioral characteristic of a person.
Answer C is incorrect because the “Digital certificate” option describes a different concept: a signed electronic credential that binds an identity to a public key.
Question 16
For Digital certificate, which statement is accurate?
Correct Answer: C
Correct Answer
Answer C is correct because the selected answer describes a signed electronic credential that binds an identity to a public key.
Incorrect Answers
Answer A is incorrect because the “Biometric authentication” option describes a different concept: Authentication based on a physical or behavioral characteristic of a person.
Answer B is incorrect because the “SSH public-key authentication” option describes a different concept: an authentication method that proves possession of a private key instead of relying only on a typed password.
Answer D is incorrect because the “Multifactor authentication” option describes a different concept: Authentication that requires evidence from two or more different factor categories.
Question 17
For Biometric authentication, which statement is accurate?
Correct Answer: A
Correct Answer
Answer A is correct because it describes authentication based on a physical or behavioral characteristic of a person.
Incorrect Answers
Answer B is incorrect because the “Multifactor authentication” option describes a different concept: Authentication that requires evidence from two or more different factor categories.
Answer C is incorrect because the “Local user account” option describes a different concept: a username and credential stored directly on a network device for authentication.
Answer D is incorrect because the “Digital certificate” option describes a different concept: a signed electronic credential that binds an identity to a public key.
Question 18
For SSH public-key authentication, which statement is accurate?
Correct Answer: C
Correct Answer
Answer C is correct because it accurately defines SSH public-key authentication. The matching definition is: An authentication method that proves possession of a private key instead of relying only on a typed password.
Incorrect Answers
Answer A is incorrect because the “Password complexity” option describes a different concept: a policy requirement that increases resistance to guessing by requiring sufficient length and character diversity.
Answer B is incorrect because the “enable secret” option describes a different concept: a Cisco IOS command that configures a hashed privileged EXEC password.
Answer D is incorrect because the “Biometric authentication” option describes a different concept: Authentication based on a physical or behavioral characteristic of a person.
Question 19
For Privilege level, which statement is accurate?
Correct Answer: D
Correct Answer
Answer D is correct because the choice accurately describes Privilege level: An IOS mechanism that controls which commands an authenticated user can execute.
Incorrect Answers
Answer A is incorrect because the “service password-encryption” option describes a different concept: a Cisco IOS feature that obfuscates certain plaintext passwords in the configuration, but is not a strong password-hashing mechanism.
Answer B is incorrect because the “Biometric authentication” option describes a different concept: Authentication based on a physical or behavioral characteristic of a person.
Answer C is incorrect because the “Digital certificate” option describes a different concept: a signed electronic credential that binds an identity to a public key.
Question 20
For Local authentication, which statement is accurate?
Correct Answer: C
Correct Answer
Answer C is correct because it describes authentication performed by checking credentials stored on the device itself rather than a central AAA server.
Incorrect Answers
Answer A is incorrect because the “Privilege level” option describes a different concept: an IOS mechanism that controls which commands an authenticated user can execute.
Answer B is incorrect because the “service password-encryption” option describes a different concept: a Cisco IOS feature that obfuscates certain plaintext passwords in the configuration, but is not a strong password-hashing mechanism.
Answer D is incorrect because the “SSH public-key authentication” option describes a different concept: an authentication method that proves possession of a private key instead of relying only on a typed password.
Question 21
During a defensive configuration review, the design calls for the following capability: A Cisco IOS command that configures a hashed privileged EXEC password. Which option names that capability most accurately?
Correct Answer: C
Correct Answer
Answer C is correct because the scenario is describing the role of enable secret. A Cisco IOS command that configures a hashed privileged EXEC password.
Incorrect Answers
Answer A is incorrect because the “Privilege level” option describes a different concept: an IOS mechanism that controls which commands an authenticated user can execute.
Answer B is incorrect because the “Local authentication” option describes a different concept: Authentication performed by checking credentials stored on the device itself rather than a central AAA server.
Answer D is incorrect because the “Password complexity” option describes a different concept: a policy requirement that increases resistance to guessing by requiring sufficient length and character diversity.
Question 22
A device must have a username and credential stored in its own configuration for a local login method. Which account type should be configured?
Correct Answer: B
Correct Answer
Answer B is correct because Local user account directly provides the function required by the scenario. A username and credential stored directly on a network device for authentication.
Incorrect Answers
Answer A is incorrect because the “Password complexity” option describes a different concept: a policy requirement that increases resistance to guessing by requiring sufficient length and character diversity.
Answer C is incorrect because the “Biometric authentication” option describes a different concept: Authentication based on a physical or behavioral characteristic of a person.
Answer D is incorrect because the “service password-encryption” option describes a different concept: a Cisco IOS feature that obfuscates certain plaintext passwords in the configuration, but is not a strong password-hashing mechanism.
Question 23
While working on an access-control investigation, an administrator encounters this requirement: A Cisco IOS feature that obfuscates certain plaintext passwords in the configuration, but is not a strong password-hashing mechanism. Which answer is the most precise match?
Correct Answer: A
Correct Answer
Answer A is correct because the operational requirement in the stem maps to service password-encryption: A Cisco IOS feature that obfuscates certain plaintext passwords in the configuration, but is not a strong password-hashing mechanism.
Incorrect Answers
Answer B is incorrect because the “SSH public-key authentication” option describes a different concept: an authentication method that proves possession of a private key instead of relying only on a typed password.
Answer C is incorrect because the “Multifactor authentication” option describes a different concept: Authentication that requires evidence from two or more different factor categories.
Answer D is incorrect because the “Privilege level” option describes a different concept: an IOS mechanism that controls which commands an authenticated user can execute.
Question 24
In a campus security deployment, the team must identify the technology that provides the following function: A policy requirement that increases resistance to guessing by requiring sufficient length and character diversity. Which option should be selected?
Correct Answer: A
Correct Answer
Answer A is correct because Password complexity is the most precise fit for the stated requirement. A policy requirement that increases resistance to guessing by requiring sufficient length and character diversity.
Incorrect Answers
Answer B is incorrect because the “Biometric authentication” option describes a different concept: Authentication based on a physical or behavioral characteristic of a person.
Answer C is incorrect because the “Local user account” option describes a different concept: a username and credential stored directly on a network device for authentication.
Answer D is incorrect because the “enable secret” option describes a different concept: a Cisco IOS command that configures a hashed privileged EXEC password.
Question 25
A login requires both a memorized password and proof of possession of a separate authenticator. Which authentication approach combines these different factor categories?
Correct Answer: C
Correct Answer
Answer C is correct because the scenario is describing the role of Multifactor authentication. Authentication that requires evidence from two or more different factor categories.
Incorrect Answers
Answer A is incorrect because the “Biometric authentication” option describes a different concept: Authentication based on a physical or behavioral characteristic of a person.
Answer B is incorrect because the “enable secret” option describes a different concept: a Cisco IOS command that configures a hashed privileged EXEC password.
Answer D is incorrect because the “Digital certificate” option describes a different concept: a signed electronic credential that binds an identity to a public key.
Question 26
During a defensive configuration review, the design calls for the following capability: A signed electronic credential that binds an identity to a public key. Which option names that capability most accurately?
Correct Answer: A
Correct Answer
Answer A is correct because Digital certificate directly provides the function required by the scenario. A signed electronic credential that binds an identity to a public key.
Incorrect Answers
Answer B is incorrect because the “SSH public-key authentication” option describes a different concept: an authentication method that proves possession of a private key instead of relying only on a typed password.
Answer C is incorrect because the “service password-encryption” option describes a different concept: a Cisco IOS feature that obfuscates certain plaintext passwords in the configuration, but is not a strong password-hashing mechanism.
Answer D is incorrect because the “Biometric authentication” option describes a different concept: Authentication based on a physical or behavioral characteristic of a person.
Question 27
A login verifies a user’s fingerprint rather than a memorized secret or a device held by the user. Which authentication method is being used?
Correct Answer: B
Correct Answer
Answer B is correct because the operational requirement in the stem maps to Biometric authentication: Authentication based on a physical or behavioral characteristic of a person.
Incorrect Answers
Answer A is incorrect because the “SSH public-key authentication” option describes a different concept: an authentication method that proves possession of a private key instead of relying only on a typed password.
Answer C is incorrect because the “enable secret” option describes a different concept: a Cisco IOS command that configures a hashed privileged EXEC password.
Answer D is incorrect because the “Password complexity” option describes a different concept: a policy requirement that increases resistance to guessing by requiring sufficient length and character diversity.
Question 28
While working on an access-control investigation, an administrator encounters this requirement: An authentication method that proves possession of a private key instead of relying only on a typed password. Which answer is the most precise match?
Correct Answer: D
Correct Answer
Answer D is correct because SSH public-key authentication is the most precise fit for the stated requirement. An authentication method that proves possession of a private key instead of relying only on a typed password.
Incorrect Answers
Answer A is incorrect because the “Local authentication” option describes a different concept: Authentication performed by checking credentials stored on the device itself rather than a central AAA server.
Answer B is incorrect because the “Password complexity” option describes a different concept: a policy requirement that increases resistance to guessing by requiring sufficient length and character diversity.
Answer C is incorrect because the “Digital certificate” option describes a different concept: a signed electronic credential that binds an identity to a public key.
Question 29
In a campus security deployment, the team must identify the technology that provides the following function: An IOS mechanism that controls which commands an authenticated user can execute. Which option should be selected?
Correct Answer: A
Correct Answer
Answer A is correct because the scenario is describing the role of Privilege level. An IOS mechanism that controls which commands an authenticated user can execute.
Incorrect Answers
Answer B is incorrect because the “Password complexity” option describes a different concept: a policy requirement that increases resistance to guessing by requiring sufficient length and character diversity.
Answer C is incorrect because the “SSH public-key authentication” option describes a different concept: an authentication method that proves possession of a private key instead of relying only on a typed password.
Answer D is incorrect because the “enable secret” option describes a different concept: a Cisco IOS command that configures a hashed privileged EXEC password.
Question 30
A router validates a login against credentials stored on the router without contacting an external AAA server. Which authentication approach is in use?
Correct Answer: C
Correct Answer
Answer C is correct because Local authentication directly provides the function required by the scenario. Authentication performed by checking credentials stored on the device itself rather than a central AAA server.
Incorrect Answers
Answer A is incorrect because the “Digital certificate” option describes a different concept: a signed electronic credential that binds an identity to a public key.
Answer B is incorrect because the “Password complexity” option describes a different concept: a policy requirement that increases resistance to guessing by requiring sufficient length and character diversity.
Answer D is incorrect because the “Local user account” option describes a different concept: a username and credential stored directly on a network device for authentication.
Popular posts
Recent Posts
