Courseiva
mediumMultiple Choice

CCNP Practice Question: Checks AAA accounting on a router: R1# show aaa…

A network engineer checks AAA accounting on a router:

R1# show aaa accounting

Accounting method list 'default': Type: exec Start-stop: group radius Accounting records: Total started: 10 Total stopped: 8 Total failed: 2 Last record: user 'admin', start time 00:01:00 UTC Mar 1 2023

Based on this output, what can be concluded?

⚠ Common exam trap

Cisco often tests the distinction between authentication and accounting configuration, and the trap here is that candidates may see 'Total failed: 2' and incorrectly assume the configuration is broken, rather than recognizing that the output still clearly shows the accounting method list is correctly set to RADIUS for EXEC sessions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Accounting is configured for EXEC sessions using RADIUS.

The output shows an accounting method list named 'default' for type 'exec' using 'group radius' with start-stop accounting. This confirms that accounting is configured for EXEC sessions (user logins) and that RADIUS is the protocol used to send accounting records. The 'Total started: 10' and 'Total stopped: 8' indicate some records were not successfully stopped, but the configuration itself is correctly identified.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    All accounting records were successfully sent.

    Why it's wrong here

    The output from the accounting configuration or status shows a failure count, indicating that two accounting records could not be delivered to the RADIUS server. Successful delivery requires an Accounting-Response from the server; if the server is unreachable or times out, the record is marked as failed. Therefore, the statement that all records were successfully sent is directly contradicted by the explicit failure counters.

  • ✓

    Accounting is configured for EXEC sessions using RADIUS.

    Why this is correct

    The running configuration includes the command 'aaa accounting exec start-stop group radius', which directs the router to generate a start accounting record when a user initiates an EXEC session (such as SSH or console) and a stop record when that session ends. The 'exec' keyword specifically applies to user shell sessions, not to network services like dot1x or VPN, and 'group radius' identifies the RADIUS server group as the destination. This matches the output and is the correct interpretation.

  • ✗

    Accounting is performed using TACACS+.

    Why it's wrong here

    The output specifies 'group radius' as the destination for accounting records, not 'group tacacs+'. Both RADIUS and TACACS+ can provide AAA, but they are distinct protocols with different ports (RADIUS uses 1812/1813, TACACS+ uses 49) and different encryption models (RADIUS encrypts only the password, while TACACS+ encrypts the entire packet). Since the configured method list references RADIUS, claiming TACACS+ is used is factually incorrect and would require a different 'aaa accounting' command.

  • ✗

    No users have logged in since accounting was enabled.

    Why it's wrong here

    The accounting output shows a count of start records, typically '10 Start Records', which are generated each time a user successfully authenticates and begins an EXEC session. If no users had logged in since accounting was enabled, there would be zero start records because a start record is only created at session initiation. This direct evidence refutes the claim that no login activity has occurred.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.