Courseiva
hardMultiple SelectObjective-mapped

300-410 Practice Question: Which TWO actions will prevent unauthorized…

Which TWO actions will prevent unauthorized access to a Cisco IOS-XE device's console port? (Choose TWO.)

⚠ Common exam trap

Cisco often tests the distinction between commands that actually prevent unauthorized access versus those that modify session behavior or apply to different line types, so the trap here is assuming that disabling idle timeout (exec-timeout 0 0) or blocking transport input enhances security, when in fact they either weaken it or are irrelevant to console port access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Configure 'login authentication default' under the console line to require AAA authentication.

Configuring 'login authentication default' under the console line forces the device to use AAA (Authentication, Authorization, and Accounting) services for console login. This prevents unauthorized access by requiring valid credentials verified by a centralized AAA server (e.g., RADIUS or TACACS+), rather than relying on a local password that could be compromised or shared.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Configure 'login authentication default' under the console line to require AAA authentication.

    Why this is correct

    This command applies the default AAA authentication method list to the console line, requiring users to authenticate before gaining access.

  • Configure 'exec-timeout 0 0' under the console line to prevent idle sessions from timing out.

    Why it's wrong here

    Setting exec-timeout to 0 0 disables the timeout, which increases the risk of unauthorized access if the console is left unattended; a non-zero timeout is recommended.

  • Configure 'transport input none' under the console line to block all inbound connections.

    Why it's wrong here

    The 'transport input' command applies to VTY lines, not the console line; the console line uses physical access only.

  • Configure 'no exec' under the console line to disable EXEC sessions on the console port.

    Why it's wrong here

    Disabling EXEC sessions on the console would prevent all administrative access, which is not a practical security measure; it would lock out the administrator.

  • Configure 'password cisco' and 'login' under the console line to require a local password.

    Why this is correct

    This sets a local password for console access and enables password checking, providing basic authentication.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1XEAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

This 300-410 question is part of Courseiva's 1,966-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.