Courseiva
Infrastructure Security →mediumMultiple Choice

300-410 Infrastructure Security Practice Question

A network administrator is configuring a Cisco IOS router to authenticate SSH users against an external TACACS+ server. The TACACS+ server is reachable at 10.10.10.5, and the shared secret is 'Cisco123'. The administrator wants to ensure that if the TACACS+ server is unreachable, a local user account 'backup' with privilege level 15 is used for authentication. Which configuration sequence correctly achieves this?

⚠ Common exam trap

The trap here is assuming that simply creating a local user account is enough for fallback, but the AAA method list must explicitly include 'local' after the TACACS+ group to enable fallback.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

aaa new-model aaa authentication login default group tacacs+ local username backup privilege 15 secret Cisco123 tacacs server TAC1 address ipv4 10.10.10.5 key Cisco123

The correct configuration must enable AAA, set the default login authentication to use TACACS+ first and then the local database, create a local user with privilege 15, and define the TACACS+ server with the correct IP and key. The fallback to local is essential for when the TACACS+ server is unreachable, and using 'secret' is best practice for storing the local password securely.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    aaa new-model aaa authentication login default group tacacs+ username backup privilege 15 secret Cisco123 tacacs server TAC1 address ipv4 10.10.10.5 key Cisco123

    Why it's wrong here

    This configuration enables AAA and configures TACACS+ authentication, but the method list only includes 'group tacacs+' without a fallback to the local database. If the TACACS+ server is unreachable, authentication will fail because there is no local fallback method specified. The local user account exists but will not be used for authentication.

  • ✗

    aaa new-model aaa authentication login default group tacacs+ local username backup privilege 15 password Cisco123 tacacs server TAC1 address ipv4 10.10.10.5 key Cisco123

    Why it's wrong here

    This configuration is almost correct, but it uses 'password' instead of 'secret' for the local user. The 'password' keyword stores the password in clear text or weakly encrypted form, while 'secret' uses a stronger encryption. Although it would work for authentication, it is less secure and not best practice. However, the requirement does not specify encryption type, so this is technically functional but not ideal.

  • ✗

    aaa new-model aaa authentication login default group tacacs+ enable username backup privilege 15 secret Cisco123 tacacs server TAC1 address ipv4 10.10.10.5 key Cisco123

    Why it's wrong here

    This configuration uses the 'enable' method as a fallback instead of the local database. The 'enable' method prompts for the enable password, not the local username/password. The requirement is to use the local user account 'backup' for fallback, so this does not meet the requirement. The local user is created but not used for authentication.

  • ✓

    aaa new-model aaa authentication login default group tacacs+ local username backup privilege 15 secret Cisco123 tacacs server TAC1 address ipv4 10.10.10.5 key Cisco123

    Why this is correct

    This configuration enables AAA, sets the default login authentication method list to try TACACS+ first and then fall back to the local database, creates a local user with privilege 15, and defines the TACACS+ server with its IP and key. This exactly meets the requirement of using TACACS+ with local fallback and a local privileged account.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

This 300-410 question is part of Courseiva's 1,401-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.