Telnet
A protocol for interactive remote terminal access that sends everything, including usernames and passwords, in cleartext. SSH replaced it for remote administration.
Telnet provides a text-based terminal session on a remote system over TCP. It was specified in RFC 854 in 1983 and listens by default on TCP port 23. Its design dates from a time when the networks it ran on were small and trusted, so it has no encryption: keystrokes, screen output, and the username and password typed at the login prompt all cross the network in cleartext. Anyone in a position to capture the traffic, through packet sniffing or a man-in-the-middle attack, can read the credentials and take over the session.
SSH replaced Telnet for remote administration because it encrypts the session, protects its integrity, authenticates the server, and can authenticate users with keys instead of passwords. Telnet still turns up on older network devices, industrial equipment and embedded systems that were never updated, and administrators sometimes use a Telnet client simply to test whether a port answers. Telnet enabled on a management interface is commonly reported as a vulnerability, alongside other cleartext protocols such as FTP.
Exam relevance: a scenario is likely to describe an administrator managing routers or servers over Telnet, or credentials captured on the wire. Candidates are expected to identify the cleartext exposure and choose SSH as the replacement, rather than a stronger password for a protocol that sends it unprotected.