300-410 Infrastructure Security Practice Question
A network administrator is configuring a Cisco IOS router to authenticate SSH users against an external TACACS+ server. The TACACS+ server is reachable at 10.10.10.5, and the shared secret is 'Cisco123'. The administrator wants to ensure that if the TACACS+ server is unreachable, a local user account 'backup' with privilege level 15 is used for authentication. Which configuration sequence correctly achieves this?
⚠ Common exam trap
The trap here is assuming that simply creating a local user account is enough for fallback, but the AAA method list must explicitly include 'local' after the TACACS+ group to enable fallback.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
aaa new-model aaa authentication login default group tacacs+ local username backup privilege 15 secret Cisco123 tacacs server TAC1 address ipv4 10.10.10.5 key Cisco123
The correct configuration must enable AAA, set the default login authentication to use TACACS+ first and then the local database, create a local user with privilege 15, and define the TACACS+ server with the correct IP and key. The fallback to local is essential for when the TACACS+ server is unreachable, and using 'secret' is best practice for storing the local password securely.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
aaa new-model aaa authentication login default group tacacs+ username backup privilege 15 secret Cisco123 tacacs server TAC1 address ipv4 10.10.10.5 key Cisco123
Why it's wrong here
This configuration enables AAA and configures TACACS+ authentication, but the method list only includes 'group tacacs+' without a fallback to the local database. If the TACACS+ server is unreachable, authentication will fail because there is no local fallback method specified. The local user account exists but will not be used for authentication.
- ✗
aaa new-model aaa authentication login default group tacacs+ local username backup privilege 15 password Cisco123 tacacs server TAC1 address ipv4 10.10.10.5 key Cisco123
Why it's wrong here
This configuration is almost correct, but it uses 'password' instead of 'secret' for the local user. The 'password' keyword stores the password in clear text or weakly encrypted form, while 'secret' uses a stronger encryption. Although it would work for authentication, it is less secure and not best practice. However, the requirement does not specify encryption type, so this is technically functional but not ideal.
- ✗
aaa new-model aaa authentication login default group tacacs+ enable username backup privilege 15 secret Cisco123 tacacs server TAC1 address ipv4 10.10.10.5 key Cisco123
Why it's wrong here
This configuration uses the 'enable' method as a fallback instead of the local database. The 'enable' method prompts for the enable password, not the local username/password. The requirement is to use the local user account 'backup' for fallback, so this does not meet the requirement. The local user is created but not used for authentication.
- ✓
aaa new-model aaa authentication login default group tacacs+ local username backup privilege 15 secret Cisco123 tacacs server TAC1 address ipv4 10.10.10.5 key Cisco123
Why this is correct
This configuration enables AAA, sets the default login authentication method list to try TACACS+ first and then fall back to the local database, creates a local user with privilege 15, and defines the TACACS+ server with its IP and key. This exactly meets the requirement of using TACACS+ with local fallback and a local privileged account.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
This 300-410 question is part of Courseiva's 1,401-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.