hardMultiple Choice
CCNP Practice Question: Is configuring a Cisco router to use TACACS+ for…
A network engineer is configuring a Cisco router to use TACACS+ for authentication and authorization of EXEC sessions. The engineer configures 'aaa new-model', 'aaa authentication login default group tacacs+ local', and 'aaa authorization exec default group tacacs+ local'. When a user tries to log in via SSH, the router prompts for username and password, but after entering correct credentials, the user is immediately disconnected. The TACACS+ server logs show that the authentication was successful. What is the most likely cause?
⚠ Common exam trap
Cisco often tests the distinction between authentication (verifying identity) and authorization (granting access/permissions), leading candidates to overlook that a successful authentication does not guarantee a successful authorization, especially when the TACACS+ server is not configured to authorize EXEC sessions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The TACACS+ server is not configured to authorize the user for EXEC access, so it sends a 'deny' response, causing the router to disconnect the user.
The TACACS+ authentication succeeded, but the user was disconnected immediately after login. This indicates that the authorization step failed. With 'aaa authorization exec default group tacacs+ local', the router sends an authorization request to the TACACS+ server for EXEC shell access. If the server responds with a 'deny' (or does not include the necessary service=shell attribute), the router denies the session and disconnects the user, even though authentication passed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The TACACS+ server is not configured to authorize the user for EXEC access, so it sends a 'deny' response, causing the router to disconnect the user.
Why this is correct
TACACS+ authorization for EXEC access is a distinct AAA phase that occurs after authentication. When the router is configured with `aaa authorization exec tacacs+`, it sends an authorization request for the EXEC service to the TACACS+ server. If the server returns a deny for service=exec, the router terminates the session immediately, even if the user's credentials were valid. This is a classic cause of 'auth succeeded, then disconnected' behavior.
- ✗
The 'aaa authorization exec' command should be 'aaa authorization commands 15' to allow the user to execute commands after login.
Why it's wrong here
`aaa authorization commands 15` is used for command authorization, which controls whether an authenticated user can run specific privileged EXEC commands after a shell has already been established. It does not determine whether the user can start an EXEC session in the first place; that is the job of `aaa authorization exec`. Since the disconnection occurs right after login and before any command is entered, changing to command authorization would not prevent the disconnect and is misdirected.
- ✗
The router's SSH configuration is missing the 'ip ssh authentication-retries' command.
Why it's wrong here
The `ip ssh authentication-retries` command sets how many times a user can attempt SSH password authentication before the connection is closed. In this scenario, the user successfully authenticates (the username/password is accepted), so the retry limit is never reached. The disconnect happens after authentication, during the TACACS+ authorization phase, which is a separate AAA transaction unrelated to SSH authentication retry mechanisms.
- ✗
The 'local' fallback in the authorization command is overriding the TACACS+ response.
Why it's wrong here
In a Cisco AAA method list like `tacacs+ local`, the `local` fallback is only consulted if the TACACS+ server returns an error or times out, not if it returns a definitive deny. A TACACS+ authorization response containing a deny is a final verdict; the router does not proceed to the next method in the list. Therefore, the local database cannot override or soften the TACACS+ denial, so the user is disconnected solely because of the server's deny response.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.