Courseiva
mediumMultiple Choice

CCNP Practice Question: A network administrator issues the following…

A network administrator issues the following command on a Cisco switch:

Switch# show aaa servers

RADIUS: id 1, priority 1, host 192.168.1.10, auth-port 1812, acct-port 1813 State: current UP, duration 3600s, previous duration 0s Dead: total 0, retransmit 0 RADIUS: id 2, priority 2, host 192.168.1.20, auth-port 1812, acct-port 1813 State: current UP, duration 100s, previous duration 300s Dead: total 3, retransmit 2

Based on this output, what can be concluded?

⚠ Common exam trap

Cisco often tests the distinction between a server's current operational state (UP/DOWN) and its historical reliability (Dead/retransmit counters), leading candidates to mistakenly assume that a 'current UP' state implies no past failures.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Server 192.168.1.20 has a history of failures.

The output shows that server 192.168.1.20 has a 'Dead: total 3' and 'retransmit 2', indicating it has been marked dead three times and two retransmissions occurred, confirming a history of failures. In contrast, server 192.168.1.10 shows 'Dead: total 0, retransmit 0', meaning it has no failure history. The 'current UP' state for both servers only reflects their present status, not their reliability history.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Both RADIUS servers are currently unreachable.

    Why it's wrong here

    The 'current UP' state in the output explicitly indicates that the RADIUS server is currently reachable and passing keepalives or health checks. A server that is unreachable would typically be marked as 'current DOWN' or have a dead counter incrementing, but both servers show a live status. Thus, this is incorrect because the current administrative and operational state is UP, not unreachable.

  • ✓

    Server 192.168.1.20 has a history of failures.

    Why this is correct

    The output shows a 'dead total' of 3 for 192.168.1.20, meaning the server has been marked dead three times. Additionally, the retransmit count of 2 indicates that on at least one occasion, two retransmissions were necessary before a response, suggesting intermittent performance or failure. While the server is currently UP, this historical data confirms past unreachability or timeouts.

  • ✗

    Server 192.168.1.10 is the backup server.

    Why it's wrong here

    In RADIUS server groups, a lower priority value (like 1) designates the primary server; the server with priority 1 is tried first and is therefore the primary, not backup. The server with a higher priority number, such as 192.168.1.20 with priority 2, would be the backup. Since 192.168.1.10 has priority 1, it is the primary server, so calling it the backup is incorrect.

  • ✗

    TACACS+ is also configured on these servers.

    Why it's wrong here

    The command output is specifically from a RADIUS server group view, showing RADIUS-specific parameters like retransmit counts, dead-total, and current status. There is no mention of TACACS+ servers or shared secrets, nor is there a separate TACACS+ configuration block. RADIUS and TACACS+ are separate AAA protocols with distinct server configurations, so asserting TACACS+ is configured on the same servers without evidence is unsupported.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.