Courseiva
Infrastructure Security →easyMultiple Choice

300-410 Infrastructure Security Practice Question

A network administrator is configuring AAA on a Cisco IOS router to authenticate administrative SSH users against a TACACS+ server. The administrator wants to ensure that if the TACACS+ server is unreachable, a locally configured user account can still be used for authentication. Which configuration should the administrator apply?

⚠ Common exam trap

The trap here is reversing the order of authentication methods or using 'none' as a fallback, which either prioritizes local accounts over TACACS+ or bypasses authentication entirely.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

aaa authentication login default group tacacs+ local

The 'aaa authentication login default group tacacs+ local' command creates a method list that tries TACACS+ first and then the local username database. This ensures that if the TACACS+ server is unreachable, administrators can still log in using locally configured credentials. The order of methods is critical: TACACS+ must be primary to maintain centralized authentication, with local as a backup for resiliency.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    aaa authentication login default group tacacs+ none

    Why it's wrong here

    Using 'none' as a fallback method means that if TACACS+ is unreachable, authentication is bypassed entirely and the user is granted access without any password verification. This is a severe security risk and does not meet the requirement of using a local user account. The 'none' keyword should be avoided in production environments.

  • ✓

    aaa authentication login default group tacacs+ local

    Why this is correct

    The 'aaa authentication login default group tacacs+ local' command configures the default login authentication method list to first attempt TACACS+ and then fall back to the local user database if the TACACS+ server does not respond. This provides the required resilience, allowing administrative access even when the TACACS+ server is unreachable, as long as a local username is configured.

  • ✗

    aaa authentication login default local group tacacs+

    Why it's wrong here

    This method list attempts local authentication first and only then TACACS+. The requirement is to use TACACS+ as the primary method and local as fallback. With this order, local accounts are checked before the TACACS+ server, which defeats centralized authentication and may allow stale local credentials to be used even when the TACACS+ server is available.

  • ✗

    aaa authentication login default group tacacs+ enable

    Why it's wrong here

    The 'enable' keyword uses the enable password as a fallback authentication method, not the local username database. This means that if TACACS+ is unreachable, users would need to enter the enable secret, which is not the desired local user account fallback. Additionally, using the enable password for login authentication is less secure and does not align with the requirement.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

One of 1,401 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.