300-410 Infrastructure Security Practice Question
A network engineer is configuring a Cisco IOS router to authenticate management users via TACACS+ using the server at 10.1.1.100 with the shared key 'Cisco123'. The engineer wants to ensure that if the TACACS+ server becomes unreachable, the router will fall back to local authentication using the local username 'admin' with password 'AdminPass'. Which configuration correctly achieves this?
⚠ Common exam trap
Many candidates confuse the TACACS+ server group name with an AAA method list name, leading to incorrect VTY line configuration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
aaa new-model tacacs server TAC1 address ipv4 10.1.1.100 key Cisco123 aaa authentication login default group tacacs+ local aaa authorization exec default group tacacs+ local line vty 0 4 login authentication default username admin privilege 15 secret AdminPass
The correct configuration enables AAA, defines the TACACS+ server, and configures the default authentication and authorization method lists to try TACACS+ first and then local. The VTY lines must reference the correct method list, and a local username must exist for fallback. The other options either omit fallback, reverse the order, or reference an invalid method list.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
aaa new-model tacacs server TAC1 address ipv4 10.1.1.100 key Cisco123 aaa authentication login default group tacacs+ aaa authorization exec default group tacacs+ line vty 0 4 login authentication default username admin privilege 15 secret AdminPass
Why it's wrong here
This configuration uses only TACACS+ for authentication and authorization without specifying a fallback method. If the TACACS+ server is unreachable, authentication will fail and local login will not be attempted. The 'local' keyword must be added to the AAA method list to enable fallback.
- ✓
aaa new-model tacacs server TAC1 address ipv4 10.1.1.100 key Cisco123 aaa authentication login default group tacacs+ local aaa authorization exec default group tacacs+ local line vty 0 4 login authentication default username admin privilege 15 secret AdminPass
Why this is correct
This configuration enables AAA with 'aaa new-model', defines a TACACS+ server, and sets authentication and authorization to use TACACS+ first, then local as fallback. The local username is created, and the VTY lines reference the default authentication list. This meets the requirement of falling back to local authentication if the server is unreachable.
- ✗
aaa new-model tacacs server TAC1 address ipv4 10.1.1.100 key Cisco123 aaa authentication login default local group tacacs+ aaa authorization exec default local group tacacs+ line vty 0 4 login authentication default username admin privilege 15 secret AdminPass
Why it's wrong here
Here, the method list attempts local authentication first, then TACACS+. This reverses the desired order: the router would always check local credentials before contacting the TACACS+ server, even when the server is available. The requirement is to use TACACS+ primarily and local only as fallback, so the order is incorrect.
- ✗
aaa new-model tacacs server TAC1 address ipv4 10.1.1.100 key Cisco123 aaa authentication login default group tacacs+ local aaa authorization exec default group tacacs+ local line vty 0 4 login authentication TAC1 username admin privilege 15 secret AdminPass
Why it's wrong here
The method list is named 'default', but the VTY lines reference 'TAC1' as the authentication list. 'TAC1' is the name of the TACACS+ server group, not an AAA method list. The 'login authentication' command expects a method list name, so this would fail because no method list named 'TAC1' exists, causing authentication to fail.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 300-410 question from scratch — 1,401 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.