Courseiva

200-301 · topic practice

Aaa practice questions

Practise CCNA 200-301 v2 Aaa practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Reviewed byJohnson Ajibi· MSc IT Security

What the exam tests

What to know about Aaa

Aaa questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Aaa exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Practice set

Aaa questions

14 questions · select your answer, then reveal the explanation

Question 1mediummultiple choice
Study the full AAA explanation →

A network administrator wants to secure remote CLI access to a Cisco router, moving beyond simple username/password authentication. Which approach best achieves this goal?

Question 2hardmultiple choice
Study the full AAA explanation →

An engineer is allowed to log in to a router but cannot enter configuration mode. Which AAA function most directly explains that outcome?

You are connected to R1. Configure AAA with RADIUS authentication so that SSH users are authenticated first against the RADIUS server (198.51.100.10) and fall back to the local user database if the server is unreachable. Additionally, troubleshoot why an 802.1X-enabled interface (GigabitEthernet0/1) remains in the unauthorized state. The RADIUS server shares a key of 'cisco123' and uses UDP port 1812. The local user 'admin' with secret 'adminpass' must be available as a fallback.

Exhibit

R1# show running-config | section aaa|radius|interface|line|username
username admin secret 5 $1$abc$defghijklmnopqrstuvwxyz12345
!
aaa new-model
aaa authentication login default group radius local
aaa authentication dot1x default group radius
!
radius server RADIUS
 address ipv4 198.51.100.10 auth-port 1812 acct-port 1813
 key cisco123
!
interface GigabitEthernet0/1
 switchport mode access
 authentication port-control auto
 dot1x pae authenticator
!
line vty 0 4
 login authentication default
 transport input ssh
!
end

R1# show dot1x interface GigabitEthernet0/1 details
Dot1x Info for GigabitEthernet0/1
-----------------------------
PAE                       = AUTHENTICATOR
PortControl               = AUTO
PortStatus                = UNAUTHORIZED
ReAuthentication          = Disabled
QuietPeriod               = 60
ServerTimeout             = 30
SuppTimeout               = 30
ReAuthMax                 = 2
MaxReq                    = 2
TxPeriod                  = 30
AuthPeriod                = 30

R1# show radius server-group all
Server group radius
  Type: Standard
  Member servers: RADIUS
  VRF: default

R1# show radius server RADIUS
Radius server: RADIUS
  Address: 198.51.100.10
  Auth Port: 1812
  Acct Port: 1813
  Timeout: 5 seconds
  Retransmit: 3
  Key: cisco123
  State: current UP
  Dead: 0
  Authentication: 0 requests, 0 timeouts, 0 failures
  Accounting: 0 requests, 0 timeouts, 0 failures
Question 4hardmultiple choice
Study the full AAA explanation →

Exhibit: Clients can see the corporate SSID but fail authentication after entering valid usernames and passwords. Which issue is the best explanation?

Exhibit

WLAN security: WPA2-Enterprise
AP log: RADIUS server timeout
SSID is visible and clients associate, but login fails
Question 5mediummultiple choice
Study the full AAA explanation →

In AAA, what does the second A stand for?

Question 6mediumdrag order
Study the full AAA explanation →

Drag and drop the following steps into the correct order to configure AAA with a RADIUS server and enable 802.1X port authentication on an IOS-XE switch.

Drag steps to the numbered slots on the right, or tap a step then tap a slot.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5
Question 7mediumdrag order
Study the full AAA explanation →

Drag and drop the following steps into the correct order to configure AAA with a RADIUS server and enable 802.1X port authentication on a Cisco IOS-XE switch.

Drag steps to the numbered slots on the right, or tap a step then tap a slot.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5
Question 8easymultiple choice
Study the full AAA explanation →

In AAA, which function determines what an authenticated user is allowed to do after login?

Question 9hardmultiple choice
Study the full AAA explanation →

A switchport is configured for 802.1X authentication. What is the usual role of the RADIUS server in that design?

Question 10mediummatching
Study the full AAA explanation →

Match each access-control term to its most accurate meaning.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Verification of identity

Determination of allowed actions

Limiting access to only what is necessary

Credential store maintained on the device itself

Question 11mediummulti select
Study the full AAA explanation →

Which THREE statements correctly describe the configuration of AAA with RADIUS or TACACS+ on Cisco IOS-XE?

Question 12hardmultiple choice
Read the full wireless explanation →

A wireless client can associate to the correct corporate SSID and authenticate successfully, but receives an address from the guest network instead of the employee network. Which troubleshooting area is strongest?

Question 13hardmultiple choice
Study the full AAA explanation →

An administrator wants to permit SSH management access but block Telnet access to a device. Which statement best reflects that design goal?

Question 14mediummultiple choice
Read the full wireless explanation →

Exhibit: Users report that they can see the corporate SSID but fail authentication immediately after entering credentials. Guest wireless works on the same access point. Which issue is most likely?

Exhibit

WLAN Corp uses WPA2-Enterprise
WLAN Guest uses WPA2-PSK
AP joined to WLC successfully
Recent event: AAA server unreachable

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Aaa sessions

Start a Aaa only practice session

Every question in these sessions is drawn from the Aaa domain — nothing else.

Related practice questions

Related 200-301 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the 200-301 exam test about Aaa?
Aaa questions test whether you can apply the concept in context, not just recognise a definition.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Aaa questions in a focused session?
Yes — the session launcher on this page draws every question from the Aaa domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other 200-301 topics?
Use the topic links above to move to related areas, or go back to the 200-301 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the 200-301 exam covers. They are not copied from any real exam or dump site.