nerdexam
Cisco

350-601 · Question #374

An engineer mus! configure the remote SSH management connectivity for Cisco Nexus 9000 Series Switches to meet these requirements: - The connectivity must be permitted from a jump host with an IP…

The correct answer is B. Option B. To permit remote SSH access from a specific jump host and allow switches to SSH to a specific subnet, the configuration must include an SSH access group permitting the jump host IP on VTY lines and an ACL for outbound connections.

Security

Question

An engineer mus! configure the remote SSH management connectivity for Cisco Nexus 9000 Series Switches to meet these requirements:

  • The connectivity must be permitted from a jump host with an IP

address of 10.10.10.10/24.

  • All switches must be permitted to connect via SSH to other devices

from the subnet of 10.20.20.0/24. Which configuration set accomplishes these requirements?

Exhibit

350-601 question #374 exhibit

Options

  • AOption A
  • BOption B
  • COption C
  • DOption D

How the community answered

(33 responses)
  • A
    12% (4)
  • B
    79% (26)
  • C
    3% (1)
  • D
    6% (2)

Why each option

To permit remote SSH access from a specific jump host and allow switches to SSH to a specific subnet, the configuration must include an SSH access group permitting the jump host IP on VTY lines and an ACL for outbound connections.

AOption A

This option is incorrect because it likely misconfigures the ACLs or applies them incorrectly, failing to meet both specified requirements for SSH connectivity.

BOption BCorrect

This option typically configures an access control list (ACL) to permit SSH access from the 10.10.10.10 jump host to the switch's VTY lines, and also ensures that outbound SSH connections originating from the switch, sourcing from the 10.20.20.0/24 subnet, are permitted to other devices within that subnet.

COption C

This option is incorrect because it probably uses incorrect ACL statements or applies them to the wrong interfaces or VTY lines, preventing the required SSH access.

DOption D

This option is incorrect because it likely has a logical flaw in the ACLs or their application, which would prevent the specified SSH connectivity from being established.

Concept tested: Cisco Nexus SSH security, VTY access, ACL configuration

Source: https://www.cisco.com/c/en/us/td/docs/switches/datacenter/nexus9000/sw/7-x/security/guide/b_Cisco_Nexus_9000_Series_NX-OS_Security_Configuration_Guide_7x/b_Cisco_Nexus_9000_Series_NX-OS_Security_Configuration_Guide_7x_chapter_010.html

Topics

#Nexus 9000#SSH Management#ACLs#Network Access Control

Community Discussion

No community discussion yet for this question.

Full 350-601 Practice