hardMultiple Choice
CCNP Practice Question: Runs the following debug on a router: R1# debug…
A network engineer runs the following debug on a router:
R1# debug aaa authentication *Mar 1 00:01:23.456: AAA/BIND(00000001): Bind iplist *Mar 1 00:01:23.456: AAA/AUTHEN/LOGIN (00000001): Pick method list 'default' *Mar 1 00:01:23.456: AAA/AUTHEN/LOGIN (00000001): Method=RADIUS *Mar 1 00:01:23.456: AAA/AUTHEN/LOGIN (00000001): RADIUS server 10.1.1.10:1812, timeout 5, retransmit 2 *Mar 1 00:01:23.456: AAA/AUTHEN/LOGIN (00000001): Sent username 'admin', password **** *Mar 1 00:01:23.456: AAA/AUTHEN/LOGIN (00000001): Received PASS response *Mar 1 00:01:23.456: AAA/AUTHEN/LOGIN (00000001): Pass
Based on this output, what can be concluded?
⚠ Common exam trap
Cisco often tests the distinction between RADIUS and TACACS+ by including port numbers or method names in debug output, and the trap here is that candidates may assume 'PASS response' could mean local authentication or fail to notice the RADIUS-specific port 1812.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The RADIUS server 10.1.1.10 authenticated the user successfully.
The debug output shows a successful AAA authentication process: the router binds to an IP list, selects the default method list, attempts RADIUS authentication against server 10.1.1.10:1812, sends the username 'admin' with a masked password, and receives a 'PASS response' followed by 'Pass'. This confirms that the RADIUS server authenticated the user successfully, making option C correct.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Authentication failed due to incorrect password.
Why it's wrong here
The debug output explicitly records 'Received PASS response' and 'Pass,' which correspond to a RADIUS Access-Accept from the server. If the password were incorrect, the RADIUS server would return an Access-Reject and the router would log something like 'Authentication failed' or 'Fail' instead. Since a PASS response was received, the password was validated successfully, so this option cannot be correct.
- ✗
The router used TACACS+ for authentication.
Why it's wrong here
The debug output shows the router communicating with a RADIUS server, as indicated by the 'radius' keyword and the server address 10.1.1.10. TACACS+ uses TCP port 49 and an entirely different packet structure, and would be labeled 'tacacs' in the debug logs. Here the authentication type is explicitly RADIUS, which is a UDP-based AAA protocol (typically ports 1812/1645).
- ✓
The RADIUS server 10.1.1.10 authenticated the user successfully.
Why this is correct
The debug output shows the RADIUS server 10.1.1.10 responding to the authentication request with a PASS response, which is the RADIUS Access-Accept message. This confirms that the server successfully authenticated the user, and the router accepts the session. The output also identifies the username as 'admin' and marks the authentication as successful with 'Pass,' so the correct answer is that the RADIUS server authenticated the user successfully.
- ✗
The user 'admin' was authenticated using local database.
Why it's wrong here
Local authentication would mean the router checks its own username/password database, and no RADIUS packets would be exchanged with 10.1.1.10. The debug output clearly shows an exchange with the RADIUS server, and the 'PASS response' comes from that server, not from the local database. Therefore, the user 'admin' was authenticated by RADIUS, not by the local database on the router.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.