Courseiva
Infrastructure Security →mediumMultiple Choice

300-410 Infrastructure Security Practice Question

A network engineer is configuring a Cisco IOS XE router to authenticate administrative SSH users against a TACACS+ server. The engineer wants to ensure that if the TACACS+ server is unreachable, a locally configured fallback account can still be used to log in. The engineer also wants to ensure that the fallback account is not used when the TACACS+ server is reachable but rejects the credentials. Which AAA configuration should the engineer apply?

⚠ Common exam trap

The trap here is thinking that local fallback is used on authentication rejection, when it is only used when the server is unreachable.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

aaa authentication login default group tacacs+ local

The method list order determines fallback behavior. Placing group tacacs+ before local ensures TACACS+ is tried first, and local is used only when the server is unreachable. If the server rejects credentials, the local method is not attempted, which satisfies both requirements. The other options either reverse the order, allow unauthenticated access, or use the enable password, none of which meet the stated goals.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    aaa authentication login default group tacacs+ local

    Why this is correct

    This method list attempts TACACS+ first and falls back to the local database only if the TACACS+ server is unreachable. If the server is reachable and rejects the credentials, the local fallback is not tried, which matches the requirement. It is the standard way to provide a backup login method while preserving server-based authentication.

  • ✗

    aaa authentication login default local group tacacs+

    Why it's wrong here

    This method list tries the local database first, so local credentials would always be used before TACACS+. That defeats the purpose of central authentication and does not match the requirement that TACACS+ be the primary method. It would also allow local accounts to bypass server-side policy even when the server is available.

  • ✗

    aaa authentication login default group tacacs+ none

    Why it's wrong here

    The none keyword allows access without any authentication if TACACS+ is unreachable, which is a severe security risk. It does not provide a local fallback account and would permit unauthenticated logins. This configuration does not meet the requirement for a secure fallback.

  • ✗

    aaa authentication login default group tacacs+ enable

    Why it's wrong here

    The enable keyword uses the enable password as a fallback, which is not a per-user account and is generally less secure. It does not provide the local username/password fallback described and may not be acceptable for administrative access. This method is deprecated in favor of local or none in many designs.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

This 300-410 question is part of Courseiva's 1,401-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.