300-410 Infrastructure Security Practice Question
A network administrator is configuring AAA on a Cisco IOS router to authenticate administrative SSH users against a TACACS+ server. The administrator wants to ensure that if the TACACS+ server is unreachable, a locally configured user account can still be used for authentication. Which configuration should the administrator apply?
⚠ Common exam trap
The trap here is reversing the order of authentication methods or using 'none' as a fallback, which either prioritizes local accounts over TACACS+ or bypasses authentication entirely.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
aaa authentication login default group tacacs+ local
The 'aaa authentication login default group tacacs+ local' command creates a method list that tries TACACS+ first and then the local username database. This ensures that if the TACACS+ server is unreachable, administrators can still log in using locally configured credentials. The order of methods is critical: TACACS+ must be primary to maintain centralized authentication, with local as a backup for resiliency.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
aaa authentication login default group tacacs+ none
Why it's wrong here
Using 'none' as a fallback method means that if TACACS+ is unreachable, authentication is bypassed entirely and the user is granted access without any password verification. This is a severe security risk and does not meet the requirement of using a local user account. The 'none' keyword should be avoided in production environments.
- ✓
aaa authentication login default group tacacs+ local
Why this is correct
The 'aaa authentication login default group tacacs+ local' command configures the default login authentication method list to first attempt TACACS+ and then fall back to the local user database if the TACACS+ server does not respond. This provides the required resilience, allowing administrative access even when the TACACS+ server is unreachable, as long as a local username is configured.
- ✗
aaa authentication login default local group tacacs+
Why it's wrong here
This method list attempts local authentication first and only then TACACS+. The requirement is to use TACACS+ as the primary method and local as fallback. With this order, local accounts are checked before the TACACS+ server, which defeats centralized authentication and may allow stale local credentials to be used even when the TACACS+ server is available.
- ✗
aaa authentication login default group tacacs+ enable
Why it's wrong here
The 'enable' keyword uses the enable password as a fallback authentication method, not the local username database. This means that if TACACS+ is unreachable, users would need to enter the enable secret, which is not the desired local user account fallback. Additionally, using the enable password for login authentication is less secure and does not align with the requirement.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
One of 1,401 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.