300-410 Infrastructure Security Practice Question
A network engineer is configuring a Cisco IOS XE router to authenticate administrative SSH users against a TACACS+ server. The engineer wants to ensure that if the TACACS+ server is unreachable, a locally configured fallback account can still be used to log in. The engineer also wants to ensure that the fallback account is not used when the TACACS+ server is reachable but rejects the credentials. Which AAA configuration should the engineer apply?
⚠ Common exam trap
The trap here is thinking that local fallback is used on authentication rejection, when it is only used when the server is unreachable.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
aaa authentication login default group tacacs+ local
The method list order determines fallback behavior. Placing group tacacs+ before local ensures TACACS+ is tried first, and local is used only when the server is unreachable. If the server rejects credentials, the local method is not attempted, which satisfies both requirements. The other options either reverse the order, allow unauthenticated access, or use the enable password, none of which meet the stated goals.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
aaa authentication login default group tacacs+ local
Why this is correct
This method list attempts TACACS+ first and falls back to the local database only if the TACACS+ server is unreachable. If the server is reachable and rejects the credentials, the local fallback is not tried, which matches the requirement. It is the standard way to provide a backup login method while preserving server-based authentication.
- ✗
aaa authentication login default local group tacacs+
Why it's wrong here
This method list tries the local database first, so local credentials would always be used before TACACS+. That defeats the purpose of central authentication and does not match the requirement that TACACS+ be the primary method. It would also allow local accounts to bypass server-side policy even when the server is available.
- ✗
aaa authentication login default group tacacs+ none
Why it's wrong here
The none keyword allows access without any authentication if TACACS+ is unreachable, which is a severe security risk. It does not provide a local fallback account and would permit unauthenticated logins. This configuration does not meet the requirement for a secure fallback.
- ✗
aaa authentication login default group tacacs+ enable
Why it's wrong here
The enable keyword uses the enable password as a fallback, which is not a per-user account and is generally less secure. It does not provide the local username/password fallback described and may not be acceptable for administrative access. This method is deprecated in favor of local or none in many designs.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
This 300-410 question is part of Courseiva's 1,401-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.