300-410 Infrastructure Security Practice Question
A network engineer is configuring a Cisco IOS router to authenticate login users against an external TACACS+ server. The engineer wants to ensure that if the TACACS+ server becomes unreachable, local authentication is used as a fallback. Which command set correctly configures this behavior on the router?
⚠ Common exam trap
Candidates often confuse the 'enable' keyword with 'local' as a fallback method; 'enable' uses the enable password, not the local user database.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
aaa authentication login default group tacacs+ local
The correct configuration must specify TACACS+ as the primary authentication method and local as the fallback. The command 'aaa authentication login default group tacacs+ local' does exactly that: it attempts TACACS+ first, and if the server is unreachable, it uses the local username database. The other options either use the wrong fallback method, reverse the order, or disable authentication.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
aaa authentication login default group tacacs+ local
Why this is correct
This command configures the default login authentication method list to first attempt TACACS+ and then fall back to the local username database if the server is unreachable. The 'group tacacs+' keyword specifies the TACACS+ server group, and 'local' provides the fallback. This meets the requirement exactly.
- ✗
aaa authentication login default group tacacs+ enable
Why it's wrong here
The 'enable' keyword configures fallback to the enable password, not the local username database. While this provides a fallback, it does not use local authentication as specified. The requirement explicitly states local authentication should be used, so this command is incorrect.
- ✗
aaa authentication login default group tacacs+ none
Why it's wrong here
The 'none' keyword disables authentication entirely if the TACACS+ server is unreachable, allowing access without credentials. This is a security risk and does not provide local fallback. The requirement is to use local authentication as fallback, so this is incorrect.
- ✗
aaa authentication login default local group tacacs+
Why it's wrong here
This command attempts local authentication first, then TACACS+. The requirement is to use TACACS+ primarily and fall back to local only if the server is unreachable. This order would bypass the TACACS+ server during normal operation, which is not desired.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
One of 1,401 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.