正解:B
The global command service password-encryption prevents supported plain-text passwords from being displayed in clear text in the running configuration. After the command is enabled, passwords configured under lines, usernames using the password keyword, and similar legacy password fields are obfuscated with Cisco Type 7 encoding. This is not strong cryptographic protection, but it does stop casual viewing of plain text during show running-config. The enable secret command protects the privileged EXEC password with a stronger hash, but it does not encrypt all plain-text passwords in the configuration. The enable password command creates a less secure privileged password, and the username Cisco password encrypt syntax is not the correct IOS command. CCNA 200-301 v1.1 Security Fundamentals expects candidates to know basic device hardening commands and the difference between enable secret and service password-encryption. The verified answer is B. Reference: Cisco IOS password encryption and secure device-management guidance.