easyMultiple ChoiceObjective-mapped
350-701 Practice Question: Wants to restrict administrative access to Cisco…
An organization wants to restrict administrative access to Cisco network devices based on the time of day and source IP address. Which technology should be used?
⚠ Common exam trap
Cisco often tests the distinction between TACACS+ and RADIUS, where candidates mistakenly choose RADIUS-based options (like 802.1X) for device administration, not realizing that TACACS+ is the only protocol that supports per-command authorization and time-based access control for CLI access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
TACACS+ with per-command authorization
TACACS+ is the correct choice because it supports per-command authorization, which allows an administrator to define granular access policies based on attributes such as time of day and source IP address. This is achieved through the TACACS+ authorization process, where the AAA server evaluates the user's request against configured authorization rules before granting access to specific commands or sessions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
TACACS+ with per-command authorization
Why this is correct
TACACS+ allows granular control over administrative access, including time and source IP.
- ✗
SNMPv3 with ACLs
Why it's wrong here
SNMPv3 secures management traffic but is not designed for administrative access control.
- ✗
802.1X with EAP-TLS
Why it's wrong here
802.1X is for network access control, not for administrative access to devices.
- ✗
IPsec VPN with extended authentication
Why it's wrong here
IPsec VPN provides encryption but does not enforce time-based policies.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
This 350-701 question is part of Courseiva's 978-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-701 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-701 exam.