Courseiva
Infrastructure Security →mediumMultiple Choice

300-410 Infrastructure Security Practice Question

A network administrator is configuring a router to authenticate with a TACACS+ server for administrative access. The administrator enters the command `aaa authentication login default group tacacs+ local` on the router. Which statement describes the authentication behavior when the TACACS+ server is reachable but rejects the user's credentials?

⚠ Common exam trap

The trap here is assuming that the local method always serves as a fallback regardless of the server's response, when in fact it is only used when the server is unreachable.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The router will deny access and will not attempt local authentication.

With the command `aaa authentication login default group tacacs+ local`, the router first attempts authentication via the TACACS+ server group. If the server is reachable and returns a rejection (e.g., invalid credentials), the router treats that as a final denial and does not fall back to the local database. The local method is used only when the TACACS+ server is unreachable (timeout or error). This ensures that a deliberate rejection by the central server is honored, preventing bypass via local accounts.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The router will deny access and will not attempt local authentication.

    Why this is correct

    This is correct because with AAA authentication, methods are tried in order, but a failure response from a method (e.g., wrong password) stops the process. The local method is used only if the TACACS+ server is unreachable (timeout/error). When the server is reachable and rejects the credentials, the router denies access immediately. This behavior prevents unauthorized access via a less secure fallback.

  • ✗

    The router will attempt local authentication first, then TACACS+ if local fails.

    Why it's wrong here

    This is incorrect because the command specifies `group tacacs+` before `local`, meaning TACACS+ is attempted first. The order of methods in the command determines the sequence. Local authentication is not attempted first; it is a fallback only if the TACACS+ server is unreachable. The router does not reorder methods based on reachability.

  • ✗

    The router will send the credentials to both TACACS+ and local simultaneously and grant access if either succeeds.

    Why it's wrong here

    This is incorrect because AAA authentication methods are evaluated sequentially, not in parallel. The router will not query both TACACS+ and the local database at the same time. It processes methods in the configured order, and a definitive failure from one method halts further processing. Simultaneous authentication is not a feature of Cisco IOS AAA.

  • ✗

    The router will fall back to the local database and authenticate the user if the local credentials are valid.

    Why it's wrong here

    Fallback to the local database occurs only when the TACACS+ server is unreachable (e.g., timeout or error), not when it actively rejects the credentials. If the server responds with an authentication failure, the router treats it as a definitive denial and does not try the next method in the list. The local method is used only if the server cannot be contacted.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

This 300-410 question is part of Courseiva's 1,401-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.