350-401 Security Practice Question
A medium-sized enterprise is migrating to a Cisco DNA Center-managed network. The security policy requires that all administrative access to network devices be authenticated via TACACS+ and that authorization for commands be enforced per user role. The network team has configured ISE as the AAA server and integrated it with DNA Center. After configuration, engineers report that they can log in to devices via SSH but are not prompted for a password when entering 'enable' mode; instead, they are granted full privileges immediately. Additionally, while in configuration mode, some engineers can issue 'debug' commands that they should not have access to. The configuration on the devices includes 'aaa new-model', 'aaa authentication login default group tacacs+ local', 'aaa authorization exec default group tacacs+ local', and 'aaa authorization commands 15 default group tacacs+ local'. What is the most likely cause of the privilege escalation and missing authorization?
⚠ Common exam trap
Cisco often tests the distinction between authentication (who you are) and authorization (what you can do), and the trap here is that candidates assume 'aaa authorization commands 15' alone enforces command restrictions, but they overlook that without 'aaa authentication enable', users may already be at privilege 15, making command authorization ineffective.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The 'aaa authentication enable default' command is missing, so the device is not requiring authentication to enter enable mode, and command authorization is not being enforced because the user is already at privilege 15.
The missing 'aaa authentication enable default group tacacs+ local' command means the device does not require TACACS+ authentication to enter enable mode. Since the user is already at privilege level 15 after login (due to the 'aaa authorization exec' command or local user configuration), they are not prompted for a password and are granted full privileges immediately. Additionally, command authorization is only configured for privilege level 15 ('aaa authorization commands 15'), so once the user is at level 15, no further authorization checks are performed for commands like 'debug', bypassing the intended per-role enforcement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The TACACS+ server is not reachable, so the device is using local authentication, but the local database has all users at privilege level 15.
Why it's wrong here
This option misidentifies the root cause. Even if TACACS+ is reachable or not, the device's local database with all users at privilege 15 would not allow users to enter enable mode without authentication if the AAA enable authentication method were properly configured. The real issue is that the 'aaa authentication enable default' command is absent, so the device uses no authentication for enable mode, making TACACS+ reachability irrelevant to the observed behavior.
- ✓
The 'aaa authentication enable default' command is missing, so the device is not requiring authentication to enter enable mode, and command authorization is not being enforced because the user is already at privilege 15.
Why this is correct
The absence of 'aaa authentication enable default' leaves the default behavior of no authentication for enable mode, allowing any user to switch to privileged EXEC without a password. Once in enable mode, the user is at privilege level 15, and if command authorization is configured for level 15, the device may not trigger an authorization check because the user already holds full privilege, or the check may occur but without prior authentication it is ineffective. This configuration flaw directly explains why no credentials are prompted and why authorization seems bypassed.
- ✗
Command authorization is only configured for privilege level 15, but users are logging in at level 1; they need 'aaa authorization commands 1 default' as well.
Why it's wrong here
This option overlooks that command authorization for privilege level 15 is intended to restrict commands executed after the user has already reached level 15. Even if users initially log in at level 1, they would normally be challenged for enable authentication to elevate their privilege; if they successfully elevate, level 15 authorization applies to their subsequent commands. Adding 'aaa authorization commands 1 default' would not fix the underlying security gap because the user never needed to pass any authentication to get to level 15.
- ✗
The 'privilege level' command is set to 15 on the VTY lines, bypassing AAA authorization.
Why it's wrong here
Setting 'privilege level 15' on VTY lines only makes the initial login session start with full privileges, but it does not, and cannot, bypass the separate AAA enable authentication mechanism. When AAA authentication is configured, the device still requires the user to authenticate before allowing enable mode, regardless of the initial privilege level. Since the missing command is 'aaa authentication enable default', this option incorrectly attributes the behavior to VTY privilege configuration and fails to address the actual authentication omission.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
SDN Controllers and Cisco ACI
Key term
REST API for Network Devices
A REST API for network devices is a set of rules that allows software applications to communicate with routers, switches, and firewalls using standard web methods like GET, POST, PUT, and DELETE over HTTP or HTTPS.
Key term
AAA on Cisco Devices
AAA on Cisco devices is a security framework that controls who can access the network, what they can do, and keeps a record of their actions.
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.