Courseiva
Infrastructure Security →mediumMultiple Choice

300-410 Infrastructure Security Practice Question

A network engineer is configuring a Cisco IOS router to authenticate administrative SSH access using TACACS+ with a backup local user account. The TACACS+ server is reachable, but the engineer wants to ensure that if the TACACS+ server becomes unreachable, the router falls back to local authentication for users who are not defined on the TACACS+ server. Which AAA configuration accomplishes this?

⚠ Common exam trap

Many exam-takers confuse the 'none' fallback method with 'local'; 'none' allows any user without authentication, while 'local' checks the local username database.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

aaa authentication login default group tacacs+ local

The correct configuration uses the 'group tacacs+ local' method list, which attempts TACACS+ authentication first and then falls back to the local username database if the TACACS+ server is unreachable. This ensures that administrators can still log in with locally defined credentials during a TACACS+ outage, maintaining access without compromising security.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    aaa authentication login default group tacacs+ local

    Why this is correct

    The 'aaa authentication login default group tacacs+ local' command configures the default method list to try TACACS+ first, then fall back to the local username database if the TACACS+ server does not respond. This meets the requirement of using local authentication as a backup when the server is unreachable.

  • ✗

    aaa authentication login default group tacacs+ none

    Why it's wrong here

    Using 'none' as the fallback method allows authentication to succeed without any credentials if the TACACS+ server is unreachable. This would permit unauthorized access, which is insecure and does not meet the requirement for local backup authentication.

  • ✗

    aaa authentication login default group tacacs+ if-needed

    Why it's wrong here

    'if-needed' is not a valid AAA authentication method keyword. The valid methods include group, local, none, enable, line, and krb5. This command would be rejected by the router, so it cannot provide the desired fallback behavior.

  • ✗

    aaa authentication login default group tacacs+ enable

    Why it's wrong here

    The 'enable' method uses the enable password for authentication, not the local username database. While it provides a fallback, it does not authenticate users against local usernames, so it fails the requirement for local user authentication.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

Courseiva writes every 300-410 question from scratch — 1,401 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.