Courseiva
Infrastructure Security →mediumMultiple Choice

300-410 Infrastructure Security Practice Question

A network engineer is configuring a Cisco IOS router to authenticate login users against an external TACACS+ server. The engineer wants to ensure that if the TACACS+ server becomes unreachable, local authentication is used as a fallback. Which command set correctly configures this behavior on the router?

⚠ Common exam trap

Candidates often confuse the 'enable' keyword with 'local' as a fallback method; 'enable' uses the enable password, not the local user database.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

aaa authentication login default group tacacs+ local

The correct configuration must specify TACACS+ as the primary authentication method and local as the fallback. The command 'aaa authentication login default group tacacs+ local' does exactly that: it attempts TACACS+ first, and if the server is unreachable, it uses the local username database. The other options either use the wrong fallback method, reverse the order, or disable authentication.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    aaa authentication login default group tacacs+ local

    Why this is correct

    This command configures the default login authentication method list to first attempt TACACS+ and then fall back to the local username database if the server is unreachable. The 'group tacacs+' keyword specifies the TACACS+ server group, and 'local' provides the fallback. This meets the requirement exactly.

  • ✗

    aaa authentication login default group tacacs+ enable

    Why it's wrong here

    The 'enable' keyword configures fallback to the enable password, not the local username database. While this provides a fallback, it does not use local authentication as specified. The requirement explicitly states local authentication should be used, so this command is incorrect.

  • ✗

    aaa authentication login default group tacacs+ none

    Why it's wrong here

    The 'none' keyword disables authentication entirely if the TACACS+ server is unreachable, allowing access without credentials. This is a security risk and does not provide local fallback. The requirement is to use local authentication as fallback, so this is incorrect.

  • ✗

    aaa authentication login default local group tacacs+

    Why it's wrong here

    This command attempts local authentication first, then TACACS+. The requirement is to use TACACS+ primarily and fall back to local only if the server is unreachable. This order would bypass the TACACS+ server during normal operation, which is not desired.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

One of 1,401 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.