With service password-encryption enabled on IOS, how does the enable secret differ from the enable password?
Choose an answer
Tap an option to check your answer.
Correct answer: The enable secret password is protected via stronger cryptography mechanisms..
Why this is the answer
The enable secret command uses MD5 hashing to protect the password, which is a one-way cryptographic function, making it significantly more secure and practically impossible to reverse engineer. In contrast, the enable password command, when service password-encryption is enabled, uses a weak, easily reversible Vigenere cipher (type 7 encryption). While both appear encrypted in the configuration, the enable secret offers robust protection, whereas the enable password provides only obfuscation. Therefore, the enable secret is always preferred for securing privileged EXEC mode access. The option stating the enable password cannot be decrypted is incorrect because type 7 encryption is easily reversible. The option claiming stronger encryption for enable password is also incorrect.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed