mediumMultiple Choice
200-201 Practice Question: A security policy requires that all remote access…
A security policy requires that all remote access be authenticated using a one-time password (OTP) token. Which technology should be implemented?
⚠ Common exam trap
The trap here is conflating any strong authentication method (SSH keys, PSK, LDAP) with OTP, when only a RADIUS-plus-token-server architecture actually validates one-time passwords.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
RADIUS with token server
RADIUS with a token server is the correct choice because RADIUS is the standard protocol for carrying authentication requests from network access devices to an authentication server, and integrating a token server (e.g., RSA SecurID, Duo) enables one-time password validation. The token server generates or validates the OTP, and RADIUS relays the credentials, satisfying the policy requirement for OTP-based remote access authentication.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
SSH key pairs
Why it's wrong here
SSH key pairs authenticate with a long-lived private key held by the client, producing no one-time password. It is tempting because SSH keys are a standard passwordless remote access mechanism, and would be correct where policy requires cryptographic key-based authentication instead of OTP tokens.
- ✓
RADIUS with token server
Why this is correct
RADIUS carries authentication requests to an external server, and pairing it with a token server lets that server validate the OTP generated by each user's hardware or software token. This satisfies the policy's requirement that all remote access use one-time passwords.
- ✗
LDAP with username and password
Why it's wrong here
LDAP with username and password authenticates with a reusable static credential, so it cannot satisfy a one-time password requirement. It is tempting because LDAP is a common directory-backed remote access authentication method, and would be correct where policy demands centralised credential management rather than OTP.
- ✗
VPN with pre-shared key
Why it's wrong here
A VPN pre-shared key is a static secret reused across sessions, so it cannot deliver a one-time password per authentication. It is tempting because VPNs commonly secure remote access, and a pre-shared key would be correct where policy mandates encrypted tunnel establishment rather than per-session OTP.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.