Courseiva
easyMultiple ChoiceObjective-mapped

350-701 Practice Question: Wants to restrict administrative access to Cisco…

An organization wants to restrict administrative access to Cisco network devices based on the time of day and source IP address. Which technology should be used?

⚠ Common exam trap

Cisco often tests the distinction between TACACS+ and RADIUS, where candidates mistakenly choose RADIUS-based options (like 802.1X) for device administration, not realizing that TACACS+ is the only protocol that supports per-command authorization and time-based access control for CLI access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

TACACS+ with per-command authorization

TACACS+ is the correct choice because it supports per-command authorization, which allows an administrator to define granular access policies based on attributes such as time of day and source IP address. This is achieved through the TACACS+ authorization process, where the AAA server evaluates the user's request against configured authorization rules before granting access to specific commands or sessions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • TACACS+ with per-command authorization

    Why this is correct

    TACACS+ allows granular control over administrative access, including time and source IP.

  • SNMPv3 with ACLs

    Why it's wrong here

    SNMPv3 secures management traffic but is not designed for administrative access control.

  • 802.1X with EAP-TLS

    Why it's wrong here

    802.1X is for network access control, not for administrative access to devices.

  • IPsec VPN with extended authentication

    Why it's wrong here

    IPsec VPN provides encryption but does not enforce time-based policies.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1XEAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

This 350-701 question is part of Courseiva's 978-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-701 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-701 exam.