mediumMultiple Choice
CCNP Practice Question: A network administrator issues the following…
A network administrator issues the following command on a Cisco switch:
Switch# show aaa servers
RADIUS: id 1, priority 1, host 192.168.1.10, auth-port 1812, acct-port 1813 State: current UP, duration 3600s, previous duration 0s Dead: total 0, retransmit 0 RADIUS: id 2, priority 2, host 192.168.1.20, auth-port 1812, acct-port 1813 State: current UP, duration 100s, previous duration 300s Dead: total 3, retransmit 2
Based on this output, what can be concluded?
⚠ Common exam trap
Cisco often tests the distinction between a server's current operational state (UP/DOWN) and its historical reliability (Dead/retransmit counters), leading candidates to mistakenly assume that a 'current UP' state implies no past failures.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Server 192.168.1.20 has a history of failures.
The output shows that server 192.168.1.20 has a 'Dead: total 3' and 'retransmit 2', indicating it has been marked dead three times and two retransmissions occurred, confirming a history of failures. In contrast, server 192.168.1.10 shows 'Dead: total 0, retransmit 0', meaning it has no failure history. The 'current UP' state for both servers only reflects their present status, not their reliability history.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Both RADIUS servers are currently unreachable.
Why it's wrong here
The 'current UP' state in the output explicitly indicates that the RADIUS server is currently reachable and passing keepalives or health checks. A server that is unreachable would typically be marked as 'current DOWN' or have a dead counter incrementing, but both servers show a live status. Thus, this is incorrect because the current administrative and operational state is UP, not unreachable.
- ✓
Server 192.168.1.20 has a history of failures.
Why this is correct
The output shows a 'dead total' of 3 for 192.168.1.20, meaning the server has been marked dead three times. Additionally, the retransmit count of 2 indicates that on at least one occasion, two retransmissions were necessary before a response, suggesting intermittent performance or failure. While the server is currently UP, this historical data confirms past unreachability or timeouts.
- ✗
Server 192.168.1.10 is the backup server.
Why it's wrong here
In RADIUS server groups, a lower priority value (like 1) designates the primary server; the server with priority 1 is tried first and is therefore the primary, not backup. The server with a higher priority number, such as 192.168.1.20 with priority 2, would be the backup. Since 192.168.1.10 has priority 1, it is the primary server, so calling it the backup is incorrect.
- ✗
TACACS+ is also configured on these servers.
Why it's wrong here
The command output is specifically from a RADIUS server group view, showing RADIUS-specific parameters like retransmit counts, dead-total, and current status. There is no mention of TACACS+ servers or shared secrets, nor is there a separate TACACS+ configuration block. RADIUS and TACACS+ are separate AAA protocols with distinct server configurations, so asserting TACACS+ is configured on the same servers without evidence is unsupported.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.