300-410 Infrastructure Security Practice Question
A network technician is configuring a Cisco IOS router to authenticate administrative users via TACACS+ using a centralized server. The requirement is that if the TACACS+ server is unreachable, the router should use the local username database for authentication. Which command sequence correctly configures this fallback behavior?
⚠ Common exam trap
The trap here is reversing the order of authentication methods, which would cause the router to use local authentication first and never query TACACS+ unless local fails.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
aaa authentication login default group tacacs+ local
The correct command is aaa authentication login default group tacacs+ local. This configures the router to attempt authentication via TACACS+ first, and if the TACACS+ server is unreachable, it falls back to the local username database. The order of methods is critical: the first method is tried, and subsequent methods are used only if the previous method fails or is unreachable.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
aaa authentication login default group tacacs+ none
Why it's wrong here
This command uses TACACS+ and then none, which means if TACACS+ is unreachable, no authentication is required, allowing access without credentials. This is insecure and does not meet the requirement to use the local database as fallback.
- ✓
aaa authentication login default group tacacs+ local
Why this is correct
This command configures AAA authentication for login to first use TACACS+ group and then fall back to the local database if the TACACS+ servers are unreachable. The order of methods is important: group tacacs+ is tried first, then local. This meets the requirement of fallback to local authentication.
- ✗
aaa authentication login default group tacacs+ enable
Why it's wrong here
This command uses TACACS+ and then the enable password as fallback. The enable password is not the local username database; it is a separate password for privileged EXEC mode. This does not meet the requirement to use the local username database for authentication.
- ✗
aaa authentication login default local group tacacs+
Why it's wrong here
This command tries local authentication first, then TACACS+. This would not use the TACACS+ server unless local authentication fails, which is the opposite of the requirement. The goal is to use TACACS+ primarily and fall back to local only if TACACS+ is unreachable.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
This 300-410 question is part of Courseiva's 1,401-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.