Courseiva
Network Services and SecurityhardMultiple ChoiceObjective-mapped

CCNA Network Services and Security Practice Question

A security team wants device administrators to log in with individual named accounts instead of sharing one generic admin account. Which security objective does that most directly improve?

⚠ Common exam trap

A frequent exam trap is selecting options unrelated to user identity and accountability, such as VLAN assignment or routing efficiency, because they sound like valid network improvements. However, these options do not address the core security goal of tracking who performed administrative actions. Candidates might also confuse accountability with performance or configuration optimization objectives, which are important but distinct. The key is to focus on the security principle that individual named accounts enable precise attribution of actions, which shared accounts cannot provide. This distinction is critical for Cisco’s security fundamentals domain and the CCNA exam.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Accountability for administrative actions

It most directly improves accountability. In practical terms, when each administrator has an individual account, the organization can tie actions to specific people rather than to one shared identity. That makes investigation, auditing, and operational review much more meaningful. This also supports better access-control hygiene overall, but the clearest direct benefit is being able to identify who actually performed an administrative action.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Accountability for administrative actions

    Why this is correct

    Creating individual accounts for device administrators directly supports accountability because each admin can be uniquely identified in audit logs. Commands, configuration changes, and login events get attributed to a specific user, making it possible to hold that individual responsible. This also enables non-repudiation and assists in forensic investigations after a security incident.

  • Automatic VLAN assignment for management traffic

    Why it's wrong here

    Automatic VLAN assignment for management traffic is determined by switchport configuration, dynamic VLAN protocols like VMPS, or IEEE 802.1X with RADIUS-based VLAN assignment. Named administrative accounts are used for authenticating logins to the device's management interface, not for deciding which VLAN carries management traffic. The two operate at different logical layers and have no direct interaction.

    When this WOULD be correct

    If the exam question asked about improving network management efficiency or optimizing traffic for management devices, then automatic VLAN assignment could be the correct answer, as it directly relates to managing network resources effectively.

  • Route summarization efficiency

    Why it's wrong here

    Route summarization efficiency is a routing protocol concept that reduces the size of routing tables by advertising aggregate prefixes. It is implemented through protocols like OSPF and EIGRP and is completely unrelated to how administrators gain access to devices. Administrative accounts only affect authentication and authorization for management plane access, not the control plane's route advertisement behavior.

    When this WOULD be correct

    In a question asking about the benefits of route summarization in a network design scenario, where multiple subnets are being aggregated to improve routing efficiency, this option would be correct. For example, a question might ask how to minimize routing table size in a large enterprise network.

  • Wireless roaming performance

    Why it's wrong here

    Wireless roaming performance depends on RF design, access point placement, client capabilities, and protocols like 802.11r fast BSS transition. It addresses how a wireless client maintains connectivity while moving between APs. Configuring individual administrative accounts for device login only secures management access and has no influence on Layer 1 radio metrics or the roaming handoff process.

    When this WOULD be correct

    In a question focused on optimizing wireless networks, if it asked about improving user experience during mobility across multiple access points, then enhancing wireless roaming performance could be the correct answer, especially in a scenario involving a large campus network.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The 200-301 exam frequently reuses these exact scenarios with slightly different constraints.

Accountability for administrative actionsCorrect answer

Why this is correct

Creating individual accounts for device administrators directly supports accountability because each admin can be uniquely identified in audit logs. Commands, configuration changes, and login events get attributed to a specific user, making it possible to hold that individual responsible. This also enables non-repudiation and assists in forensic investigations after a security incident.

Automatic VLAN assignment for management trafficWrong answer — click to see why

Why this is wrong here

Named accounts are a security measure for authentication and authorization, not a mechanism for VLAN assignment. VLAN assignment is typically handled by switchport configuration, 802.1X, or dynamic VLAN protocols like VMPS, and is unrelated to the identity of the administrator logging in.

★ When this WOULD be the correct answer

If the exam question asked about improving network management efficiency or optimizing traffic for management devices, then automatic VLAN assignment could be the correct answer, as it directly relates to managing network resources effectively.

Why candidates choose this

Students might confuse the concept of individual accounts with user-based VLAN assignment in 802.1X, where individual users are assigned to specific VLANs. However, the question is about administrative login accounts, not end-user network access.

Route summarization efficiencyWrong answer — click to see why

Why this is wrong here

Route summarization is a routing protocol technique used to reduce the size of routing tables and improve network efficiency. It has no connection to administrative account management or security objectives like accountability.

★ When this WOULD be the correct answer

In a question asking about the benefits of route summarization in a network design scenario, where multiple subnets are being aggregated to improve routing efficiency, this option would be correct. For example, a question might ask how to minimize routing table size in a large enterprise network.

Why candidates choose this

A test-taker might think that 'summarization' relates to logging or summarizing actions, but in networking, summarization specifically refers to route aggregation, not audit logs.

Wireless roaming performanceWrong answer — click to see why

Why this is wrong here

Wireless roaming performance depends on factors like AP placement, signal strength, and roaming protocols (e.g., 802.11r). Administrative account design does not affect how client devices roam between access points.

★ When this WOULD be the correct answer

In a question focused on optimizing wireless networks, if it asked about improving user experience during mobility across multiple access points, then enhancing wireless roaming performance could be the correct answer, especially in a scenario involving a large campus network.

Why candidates choose this

Students might associate 'individual accounts' with 'individual user profiles' in wireless networks, but the question is about device administrators, not wireless clients. The context is administrative access, not wireless performance.

Analysis generated from the official 200-301blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Visual reference

Switch VLAN 10 Sales (192.168.10.0/24) PC-A PC-B VLAN 20 HR (192.168.20.0/24) PC-C PC-D Router VLANs isolate traffic — inter-VLAN routing requires a Layer 3 device

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1XEAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

This 200-301 question is part of Courseiva's 1,389-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.