Courseiva
Infrastructure →mediumMultiple Choice

350-401 Infrastructure Practice Question

A network administrator is configuring a Cisco IOS router to authenticate management users via TACACS+. The TACACS+ server is reachable at 10.1.1.100. The administrator wants to ensure that if the TACACS+ server becomes unreachable, the router will fall back to local authentication using the local username 'admin' with password 'Cisco123'. Which configuration should be applied?

⚠ Common exam trap

The trap here is forgetting to include the 'local' keyword as a fallback method, which would cause authentication to fail if the TACACS+ server is unreachable.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

aaa new-model aaa authentication login default group tacacs+ local tacacs server TAC1 address ipv4 10.1.1.100 key SecretKey username admin privilege 15 secret Cisco123

The correct configuration enables AAA, specifies TACACS+ with local fallback in the authentication method list, defines the TACACS+ server using the modern 'tacacs server' command, and creates a local username with a secret. This ensures authentication works even if the TACACS+ server is down.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    aaa new-model aaa authentication login default group tacacs+ local tacacs server TAC1 address ipv4 10.1.1.100 key SecretKey username admin privilege 15 secret Cisco123

    Why this is correct

    This configuration enables AAA, sets the default login authentication method list to use TACACS+ first and then local as fallback, defines the TACACS+ server, and creates a local username. This ensures that if the TACACS+ server is unreachable, the router will use the local database for authentication.

  • ✗

    aaa new-model aaa authentication login default group tacacs+ local tacacs-server host 10.1.1.100 key SecretKey username admin privilege 15 secret Cisco123

    Why it's wrong here

    The command 'tacacs-server host' is deprecated in favor of the 'tacacs server' configuration mode. While it may still work, it is not the recommended method for modern Cisco IOS. The other commands are correct, but this option uses legacy syntax.

  • ✗

    aaa new-model aaa authentication login default group tacacs+ tacacs server TAC1 address ipv4 10.1.1.100 key SecretKey username admin privilege 15 secret Cisco123

    Why it's wrong here

    This configuration does not include the 'local' keyword in the AAA authentication method list. Without it, if the TACACS+ server is unreachable, authentication will fail because there is no fallback method. The local username is defined but not used for authentication.

  • ✗

    aaa new-model aaa authentication login default group tacacs+ local tacacs server TAC1 address ipv4 10.1.1.100 key SecretKey username admin privilege 15 password Cisco123

    Why it's wrong here

    The use of 'password' instead of 'secret' stores the password in clear text or weak encryption, which is insecure. While the AAA configuration is correct, the local username should use 'secret' for stronger encryption. This option is less secure and not recommended.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.