300-410 Infrastructure Security Practice Question
A network administrator is configuring a router to authenticate with a TACACS+ server for administrative access. The administrator enters the command `aaa authentication login default group tacacs+ local` on the router. Which statement describes the authentication behavior when the TACACS+ server is reachable but rejects the user's credentials?
⚠ Common exam trap
The trap here is assuming that the local method always serves as a fallback regardless of the server's response, when in fact it is only used when the server is unreachable.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The router will deny access and will not attempt local authentication.
With the command `aaa authentication login default group tacacs+ local`, the router first attempts authentication via the TACACS+ server group. If the server is reachable and returns a rejection (e.g., invalid credentials), the router treats that as a final denial and does not fall back to the local database. The local method is used only when the TACACS+ server is unreachable (timeout or error). This ensures that a deliberate rejection by the central server is honored, preventing bypass via local accounts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The router will deny access and will not attempt local authentication.
Why this is correct
This is correct because with AAA authentication, methods are tried in order, but a failure response from a method (e.g., wrong password) stops the process. The local method is used only if the TACACS+ server is unreachable (timeout/error). When the server is reachable and rejects the credentials, the router denies access immediately. This behavior prevents unauthorized access via a less secure fallback.
- ✗
The router will attempt local authentication first, then TACACS+ if local fails.
Why it's wrong here
This is incorrect because the command specifies `group tacacs+` before `local`, meaning TACACS+ is attempted first. The order of methods in the command determines the sequence. Local authentication is not attempted first; it is a fallback only if the TACACS+ server is unreachable. The router does not reorder methods based on reachability.
- ✗
The router will send the credentials to both TACACS+ and local simultaneously and grant access if either succeeds.
Why it's wrong here
This is incorrect because AAA authentication methods are evaluated sequentially, not in parallel. The router will not query both TACACS+ and the local database at the same time. It processes methods in the configured order, and a definitive failure from one method halts further processing. Simultaneous authentication is not a feature of Cisco IOS AAA.
- ✗
The router will fall back to the local database and authenticate the user if the local credentials are valid.
Why it's wrong here
Fallback to the local database occurs only when the TACACS+ server is unreachable (e.g., timeout or error), not when it actively rejects the credentials. If the server responds with an authentication failure, the router treats it as a definitive denial and does not try the next method in the list. The local method is used only if the server cannot be contacted.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
This 300-410 question is part of Courseiva's 1,401-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.