mediumMultiple Choice
CCNP Practice Question: A network administrator runs the following…
A network administrator runs the following command on a switch:
Switch# show aaa method-list
Method List Name: default Type: authentication Group: radius Group: local Method List Name: console Type: authentication Group: local Method List Name: default Type: authorization Group: tacacs+ Group: local
Based on this output, what can be concluded?
⚠ Common exam trap
Cisco often tests the distinction between authentication and authorization method lists; the trap here is assuming that the default authorization list's use of TACACS+ implies it is also used for authentication, when in fact the authentication default list uses RADIUS.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
RADIUS is the primary authentication method for default login.
The output shows that the default method list for authentication uses RADIUS as the first method and local as the fallback. Since 'default' applies to all lines and services that do not have a named list, RADIUS is the primary authentication method for default login. Option C correctly identifies this primary role of RADIUS.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Authorization for all users uses RADIUS.
Why it's wrong here
The authorization function for this router is bound to TACACS+, as seen in the aaa authorization exec statement, not RADIUS. RADIUS is present only as the authentication server, meaning it verifies login credentials; it never performs the post-login authorization that determines user privileges or command access. Therefore the statement incorrectly assigns a RADIUS role to the authorization phase, which in this configuration belongs exclusively to TACACS+ (with local fallback).
- ✗
Console authentication uses RADIUS as fallback.
Why it's wrong here
The console line is configured with an authentication list that uses only the local user database, without any RADIUS server entries. This contrasts with the default list used on VTY lines, where RADIUS is the primary method. Since no server fallback is defined for console access, a user cannot be authenticated via RADIUS even if the local database lacks the account; access is strictly limited to the locally defined credentials.
- ✓
RADIUS is the primary authentication method for default login.
Why this is correct
Within the default authentication method list, group radius appears as the first method, so when a new session triggers authentication, the device forwards the credentials to the RADIUS server before considering local or any other fallback. This makes RADIUS the primary source of truth for verifying usernames and passwords for default login, which typically applies to remote VTY users. Only if RADIUS cannot be reached or the server responds with an error would the later methods be attempted.
- ✗
TACACS+ is used for authentication.
Why it's wrong here
The aaa authentication list for default login references the RADIUS server group as the first method and local as a fallback; TACACS+ never appears in any aaa authentication statement. Instead, TACACS+ is referenced exclusively in the aaa authorization statements, which governs what authenticated users may do after login, such as enabling privileged EXEC mode. Thus, while TACACS+ is an AAA protocol on this device, it is not used to check login credentials, making the claim false.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.