hardMultiple Choice
CCNP Practice Question: Checks the AAA server status: R1# show aaa…
A network engineer checks the AAA server status:
R1# show aaa servers
RADIUS: id 1, priority 1, host 10.1.1.10, auth-port 1812, acct-port 1813 State: current DEAD, duration 0s, previous duration 500s Dead: total 1, retransmit 3 RADIUS: id 2, priority 2, host 10.1.1.20, auth-port 1812, acct-port 1813 State: current UP, duration 200s, previous duration 0s Dead: total 0, retransmit 0
Based on this output, what can be concluded?
⚠ Common exam trap
Cisco often tests the misinterpretation of 'Dead: total 1' as meaning the server is currently dead for the first time, when in fact it indicates the cumulative number of times the server has transitioned to a dead state, not the current status.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The backup server is currently handling authentication.
The output shows that the primary RADIUS server (10.1.1.10) is in a DEAD state, while the backup server (10.1.1.20) is UP and has been handling authentication for 200 seconds. This confirms that the backup server is currently processing AAA requests, making option B correct.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Both RADIUS servers are operational.
Why it's wrong here
The output lists the RADIUS servers with a state field, and the primary server's state is shown as DEAD. A DEAD RADIUS server is non-operational because it has failed to respond to keepalives or active probes, so it is not eligible to handle authentication requests. Therefore, it is factually incorrect to claim that both servers are operational.
- ✓
The backup server is currently handling authentication.
Why this is correct
The primary RADIUS server is marked DEAD, so the IOS RADIUS failover mechanism automatically routes authentication requests to the next configured server, which is the backup. The output shows the backup server with an UP state and active request counts, confirming it is the one currently handling authentication. This is the expected and correct condition during a primary-server outage.
- ✗
The primary server has never failed before.
Why it's wrong here
The output includes a 'Dead Total' counter (or similar) showing 1, which records the number of times the server has transitioned to the dead state. That counter is incremented each time the server fails to respond, and the current dead status itself is not the first occurrence. Thus, the claim that the primary server has never failed before is directly contradicted by the dead-total counter.
- ✗
TACACS+ is also configured on these servers.
Why it's wrong here
This show command output specifically displays RADIUS server entries and their statuses; it contains no TACACS+ server definitions, shared-secret fields, or TACACS+ protocol statistics. TACACS+ and RADIUS are separate AAA protocols with distinct server configurations, and viewing RADIUS servers gives no evidence that TACACS+ is also configured on those same IP addresses. Making that assumption confuses protocol-specific AAA configuration with a generic server list.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.