To protect the password for VTY lines against over-the-shoulder attacks, the configuration should include 'service password-encryption'. This command encrypts all plaintext passwords in the configuration file, making them less susceptible to shoulder-surfing attacks789. References := Cisco Community discussions and Cisco's official documentation on securing VTY lines