Courseiva
Infrastructure Security →easyMultiple Choice

300-410 Infrastructure Security Practice Question

A network technician is configuring a Cisco IOS router to authenticate administrative users via TACACS+ using a centralized server. The requirement is that if the TACACS+ server is unreachable, the router should use the local username database for authentication. Which command sequence correctly configures this fallback behavior?

⚠ Common exam trap

The trap here is reversing the order of authentication methods, which would cause the router to use local authentication first and never query TACACS+ unless local fails.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

aaa authentication login default group tacacs+ local

The correct command is aaa authentication login default group tacacs+ local. This configures the router to attempt authentication via TACACS+ first, and if the TACACS+ server is unreachable, it falls back to the local username database. The order of methods is critical: the first method is tried, and subsequent methods are used only if the previous method fails or is unreachable.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    aaa authentication login default group tacacs+ none

    Why it's wrong here

    This command uses TACACS+ and then none, which means if TACACS+ is unreachable, no authentication is required, allowing access without credentials. This is insecure and does not meet the requirement to use the local database as fallback.

  • ✓

    aaa authentication login default group tacacs+ local

    Why this is correct

    This command configures AAA authentication for login to first use TACACS+ group and then fall back to the local database if the TACACS+ servers are unreachable. The order of methods is important: group tacacs+ is tried first, then local. This meets the requirement of fallback to local authentication.

  • ✗

    aaa authentication login default group tacacs+ enable

    Why it's wrong here

    This command uses TACACS+ and then the enable password as fallback. The enable password is not the local username database; it is a separate password for privileged EXEC mode. This does not meet the requirement to use the local username database for authentication.

  • ✗

    aaa authentication login default local group tacacs+

    Why it's wrong here

    This command tries local authentication first, then TACACS+. This would not use the TACACS+ server unless local authentication fails, which is the opposite of the requirement. The goal is to use TACACS+ primarily and fall back to local only if TACACS+ is unreachable.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

This 300-410 question is part of Courseiva's 1,401-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.