easyMultiple ChoiceObjective-mapped
200-201 Practice Question: A network administrator is using Cisco ISE to…
A network administrator is using Cisco ISE to monitor endpoint authentication. Which report provides details on failed authentication attempts and the reasons?
⚠ Common exam trap
Cisco often tests the distinction between RADIUS Authentication (which captures failures and reasons) and RADIUS Accounting (which tracks session usage), leading candidates to mistakenly choose the Accounting report when asked about failed authentications.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
RADIUS Authentication Report
The RADIUS Authentication Report in Cisco ISE specifically logs all authentication attempts, including failures, and provides detailed reasons for each failure (e.g., invalid credentials, user not found, or authorization policy mismatch). This report is the primary tool for troubleshooting failed authentications because it captures the RADIUS Access-Reject messages and the corresponding failure reasons from the ISE policy evaluation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
RADIUS Authentication Report
Why this is correct
This report includes details of authentication attempts and failure reasons.
- ✗
Endpoint Profiler Report
Why it's wrong here
This report shows device profiling information, not authentication details.
- ✗
RADIUS Accounting Report
Why it's wrong here
This report shows accounting data (session time, bytes), not authentication failures.
- ✗
Active Session Report
Why it's wrong here
This report shows currently active sessions, not failed attempts.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
One of 979 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.