mediumMultiple Choice
CCNP Practice Question: Checks AAA accounting on a router: R1# show aaa…
A network engineer checks AAA accounting on a router:
R1# show aaa accounting
Accounting method list 'default': Type: exec Start-stop: group radius Accounting records: Total started: 10 Total stopped: 8 Total failed: 2 Last record: user 'admin', start time 00:01:00 UTC Mar 1 2023
Based on this output, what can be concluded?
⚠ Common exam trap
Cisco often tests the distinction between authentication and accounting configuration, and the trap here is that candidates may see 'Total failed: 2' and incorrectly assume the configuration is broken, rather than recognizing that the output still clearly shows the accounting method list is correctly set to RADIUS for EXEC sessions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Accounting is configured for EXEC sessions using RADIUS.
The output shows an accounting method list named 'default' for type 'exec' using 'group radius' with start-stop accounting. This confirms that accounting is configured for EXEC sessions (user logins) and that RADIUS is the protocol used to send accounting records. The 'Total started: 10' and 'Total stopped: 8' indicate some records were not successfully stopped, but the configuration itself is correctly identified.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
All accounting records were successfully sent.
Why it's wrong here
The output from the accounting configuration or status shows a failure count, indicating that two accounting records could not be delivered to the RADIUS server. Successful delivery requires an Accounting-Response from the server; if the server is unreachable or times out, the record is marked as failed. Therefore, the statement that all records were successfully sent is directly contradicted by the explicit failure counters.
- ✓
Accounting is configured for EXEC sessions using RADIUS.
Why this is correct
The running configuration includes the command 'aaa accounting exec start-stop group radius', which directs the router to generate a start accounting record when a user initiates an EXEC session (such as SSH or console) and a stop record when that session ends. The 'exec' keyword specifically applies to user shell sessions, not to network services like dot1x or VPN, and 'group radius' identifies the RADIUS server group as the destination. This matches the output and is the correct interpretation.
- ✗
Accounting is performed using TACACS+.
Why it's wrong here
The output specifies 'group radius' as the destination for accounting records, not 'group tacacs+'. Both RADIUS and TACACS+ can provide AAA, but they are distinct protocols with different ports (RADIUS uses 1812/1813, TACACS+ uses 49) and different encryption models (RADIUS encrypts only the password, while TACACS+ encrypts the entire packet). Since the configured method list references RADIUS, claiming TACACS+ is used is factually incorrect and would require a different 'aaa accounting' command.
- ✗
No users have logged in since accounting was enabled.
Why it's wrong here
The accounting output shows a count of start records, typically '10 Start Records', which are generated each time a user successfully authenticates and begins an EXEC session. If no users had logged in since accounting was enabled, there would be zero start records because a start record is only created at session initiation. This direct evidence refutes the claim that no login activity has occurred.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.