Courseiva
Network Services and SecurityhardMultiple ChoiceObjective-mapped

CCNA Network Services and Security Practice Question

Why is the combination of strong authentication and centralized logging better than either control by itself?

⚠ Common exam trap

A common exam trap is believing that strong authentication alone is enough to secure a network, leading to the misconception that event logging is unnecessary. Candidates may also incorrectly assume that centralized logging can replace authentication by simply recording events without preventing unauthorized access. This misunderstanding overlooks the complementary roles these controls play: authentication stops unauthorized users upfront, while logging provides the visibility needed to detect and investigate incidents. Ignoring either control weakens overall security and can cause candidates to select incorrect answers that underestimate the importance of layered defenses.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Authentication improves prevention, while centralized logging improves visibility and investigation.

The combination is better because strong authentication helps prevent unauthorized access, while centralized logging helps detect, review, and investigate what happened across the environment. In practical terms, one control is stronger on prevention, and the other is stronger on visibility and accountability. Together they provide broader protection than either one alone. This reflects a real security principle: mature security depends on layers of control, not one mechanism trying to do every job.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Authentication improves prevention, while centralized logging improves visibility and investigation.

    Why this is correct

    Strong authentication (e.g., MFA, certificates) enforces identity verification before access is granted, thereby reducing the likelihood of unauthorized entry—this is a preventive control. Centralized logging, by contrast, aggregates security events from diverse systems into a single repository, enabling real-time monitoring, forensic analysis, and post-incident investigation. Together they form a defense-in-depth strategy: one blocks initial compromise, while the other provides the visibility needed to detect, respond to, and learn from attempted or successful attacks.

  • They are redundant because both perform exactly the same task.

    Why it's wrong here

    Authentication and centralized logging are not redundant because they address different security functions: authentication is a preventive control that verifies identity before access is granted, while logging is a detective control that records activity for after-the-fact review. They operate at different points in the security lifecycle—one stops unauthorized access, the other reveals what happened when controls are challenged. Thus, they are complementary layers, not interchangeable duplicate mechanisms; removing either would leave distinct gaps in a security posture.

    When this WOULD be correct

    In a question that asks about the efficiency of security measures in a highly controlled environment, where both strong authentication and logging are implemented to achieve the same goal of access control, option B could be correct if the context implies that they are used interchangeably without recognizing their distinct roles.

  • Centralized logging makes authentication unnecessary.

    Why it's wrong here

    Centralized logging merely records events after they occur and has no capability to enforce access restrictions or verify user identity. Without authentication, anyone could gain direct access to systems, and logs would simply provide a record of the resulting unauthorized activity—offering no protection whatsover. Logging is a detective control, not a preventive one; it cannot replace identity verification, which remains the essential front-line defense against unauthorized access. Additionally, logs are only meaningful if the system already restricts who can perform actions, which relies on authentication.

    When this WOULD be correct

    If the exam question were to ask about a scenario where centralized logging is implemented in a highly secure environment that relies solely on logging for access control, then this option could be considered correct. For example, a question might describe a system where access is granted based on log entries rather than traditional authentication methods.

  • Strong authentication removes the need for any event records.

    Why it's wrong here

    Event records remain indispensable even when robust authentication mechanisms like smart cards or biometrics are in place. Authentication failures, successful logins, privilege escalations, and anomalous usage patterns are all captured in logs, which are critical for detecting compromised credentials, insider misuse, and policy violations. Furthermore, strong authentication can fail or be bypassed through techniques like token theft or social engineering, and logs are often the only source of evidence to uncover such incidents and support compliance auditing.

    When this WOULD be correct

    In a scenario where the exam question specifically states that strong authentication methods are infallible and cannot be bypassed, one might argue that event records are redundant. This would imply that if authentication is always successful, there is no need to log events.

Option-by-option analysis

Why each answer is right or wrong

Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The 200-301 exam frequently reuses these exact scenarios with slightly different constraints.

Authentication improves prevention, while centralized logging improves visibility and investigation.Correct answer

Why this is correct

Strong authentication (e.g., MFA, certificates) enforces identity verification before access is granted, thereby reducing the likelihood of unauthorized entry—this is a preventive control. Centralized logging, by contrast, aggregates security events from diverse systems into a single repository, enabling real-time monitoring, forensic analysis, and post-incident investigation. Together they form a defense-in-depth strategy: one blocks initial compromise, while the other provides the visibility needed to detect, respond to, and learn from attempted or successful attacks.

They are redundant because both perform exactly the same task.Wrong answer — click to see why

Why this is wrong here

Option B is incorrect because strong authentication and centralized logging serve different purposes; authentication secures access, while logging provides oversight and accountability. They complement each other rather than being redundant.

★ When this WOULD be the correct answer

In a question that asks about the efficiency of security measures in a highly controlled environment, where both strong authentication and logging are implemented to achieve the same goal of access control, option B could be correct if the context implies that they are used interchangeably without recognizing their distinct roles.

Why candidates choose this

Candidates may choose this option due to a misunderstanding of security concepts, believing that if both controls aim to enhance security, they must be performing the same function, leading to confusion about their specific roles.

Centralized logging makes authentication unnecessary.Wrong answer — click to see why

Why this is wrong here

This option is incorrect because centralized logging does not eliminate the need for authentication; rather, both are complementary security measures that serve different purposes in a security framework.

★ When this WOULD be the correct answer

If the exam question were to ask about a scenario where centralized logging is implemented in a highly secure environment that relies solely on logging for access control, then this option could be considered correct. For example, a question might describe a system where access is granted based on log entries rather than traditional authentication methods.

Why candidates choose this

Candidates might choose this option due to a misunderstanding of the roles of authentication and logging, believing that logging alone can suffice for security, especially if they have encountered scenarios where logging is emphasized without adequate authentication.

Strong authentication removes the need for any event records.Wrong answer — click to see why

Why this is wrong here

This option is wrong because strong authentication does not eliminate the need for event records; both are essential for a comprehensive security posture. Event records are crucial for auditing and incident response, regardless of authentication strength.

★ When this WOULD be the correct answer

In a scenario where the exam question specifically states that strong authentication methods are infallible and cannot be bypassed, one might argue that event records are redundant. This would imply that if authentication is always successful, there is no need to log events.

Why candidates choose this

Candidates may find this option tempting because they might believe that robust authentication alone could sufficiently secure a system, leading them to overlook the importance of logging for monitoring and incident response.

Analysis generated from the official 200-301blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1XEAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

Courseiva writes every 200-301 question from scratch — 1,389 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-301 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-301 exam.