Courseiva
mediumMultiple Choice

200-201 Practice Question: A security policy requires that all remote access…

A security policy requires that all remote access be authenticated using a one-time password (OTP) token. Which technology should be implemented?

⚠ Common exam trap

The trap here is conflating any strong authentication method (SSH keys, PSK, LDAP) with OTP, when only a RADIUS-plus-token-server architecture actually validates one-time passwords.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

RADIUS with token server

RADIUS with a token server is the correct choice because RADIUS is the standard protocol for carrying authentication requests from network access devices to an authentication server, and integrating a token server (e.g., RSA SecurID, Duo) enables one-time password validation. The token server generates or validates the OTP, and RADIUS relays the credentials, satisfying the policy requirement for OTP-based remote access authentication.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    SSH key pairs

    Why it's wrong here

    SSH key pairs authenticate with a long-lived private key held by the client, producing no one-time password. It is tempting because SSH keys are a standard passwordless remote access mechanism, and would be correct where policy requires cryptographic key-based authentication instead of OTP tokens.

  • ✓

    RADIUS with token server

    Why this is correct

    RADIUS carries authentication requests to an external server, and pairing it with a token server lets that server validate the OTP generated by each user's hardware or software token. This satisfies the policy's requirement that all remote access use one-time passwords.

  • ✗

    LDAP with username and password

    Why it's wrong here

    LDAP with username and password authenticates with a reusable static credential, so it cannot satisfy a one-time password requirement. It is tempting because LDAP is a common directory-backed remote access authentication method, and would be correct where policy demands centralised credential management rather than OTP.

  • ✗

    VPN with pre-shared key

    Why it's wrong here

    A VPN pre-shared key is a static secret reused across sessions, so it cannot deliver a one-time password per authentication. It is tempting because VPNs commonly secure remote access, and a pre-shared key would be correct where policy mandates encrypted tunnel establishment rather than per-session OTP.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.