300-410 Infrastructure Security Practice Question
A network engineer is configuring a Cisco IOS router to authenticate administrative SSH access using TACACS+ with a backup local user account. The TACACS+ server is reachable, but the engineer wants to ensure that if the TACACS+ server becomes unreachable, the router falls back to local authentication for users who are not defined on the TACACS+ server. Which AAA configuration accomplishes this?
⚠ Common exam trap
Many exam-takers confuse the 'none' fallback method with 'local'; 'none' allows any user without authentication, while 'local' checks the local username database.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
aaa authentication login default group tacacs+ local
The correct configuration uses the 'group tacacs+ local' method list, which attempts TACACS+ authentication first and then falls back to the local username database if the TACACS+ server is unreachable. This ensures that administrators can still log in with locally defined credentials during a TACACS+ outage, maintaining access without compromising security.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
aaa authentication login default group tacacs+ local
Why this is correct
The 'aaa authentication login default group tacacs+ local' command configures the default method list to try TACACS+ first, then fall back to the local username database if the TACACS+ server does not respond. This meets the requirement of using local authentication as a backup when the server is unreachable.
- ✗
aaa authentication login default group tacacs+ none
Why it's wrong here
Using 'none' as the fallback method allows authentication to succeed without any credentials if the TACACS+ server is unreachable. This would permit unauthorized access, which is insecure and does not meet the requirement for local backup authentication.
- ✗
aaa authentication login default group tacacs+ if-needed
Why it's wrong here
'if-needed' is not a valid AAA authentication method keyword. The valid methods include group, local, none, enable, line, and krb5. This command would be rejected by the router, so it cannot provide the desired fallback behavior.
- ✗
aaa authentication login default group tacacs+ enable
Why it's wrong here
The 'enable' method uses the enable password for authentication, not the local username database. While it provides a fallback, it does not authenticate users against local usernames, so it fails the requirement for local user authentication.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 300-410 question from scratch — 1,401 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.