Letting the command prompt you for the password is more secure, since it avoids having the password stored in the command log. I only insert the password in the command line if I'm running it non-interactively (from a script).
ST: Just try it and see if it works. The only way it could hurt anything would be if you typed in the name of the wrong database, which could overwrite that database.