350-401 Infrastructure Practice Question
A network administrator is configuring a Cisco IOS router to authenticate management users via TACACS+. The router must use the TACACS+ server at 10.1.1.100 with the shared secret 'Cisco123'. The administrator wants to ensure that if the TACACS+ server is unreachable, authentication falls back to the local database. Which configuration is required?
⚠ Common exam trap
The trap here is the order of methods in the AAA authentication command; placing 'local' before 'group tacacs+' changes the fallback behavior and may inadvertently allow local credentials to be used even when the TACACS+ server is available.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
aaa authentication login default group tacacs+ local
The correct command is 'aaa authentication login default group tacacs+ local'. It configures the default method list to attempt TACACS+ authentication first, and if the TACACS+ server is unreachable, it falls back to the local username and password database. This provides redundancy while maintaining individual user accountability.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
aaa authentication login default group tacacs+ none
Why it's wrong here
This command specifies TACACS+ first, but if the server is unreachable, it uses 'none', which means no authentication is required. This is a security risk and does not meet the requirement to fall back to the local database. The 'none' keyword allows access without credentials, which is not acceptable for management access. Therefore, this is incorrect.
- ✗
aaa authentication login default group tacacs+ enable
Why it's wrong here
This command uses TACACS+ first, and if the server is unreachable, it falls back to the enable password. The requirement is to fall back to the local database, not the enable password. The enable password is a single password for privileged exec mode and does not provide individual user authentication. Thus, this does not meet the requirement.
- ✗
aaa authentication login default local group tacacs+
Why it's wrong here
This command lists 'local' before 'group tacacs+', meaning the router will check the local database first. If the local database does not have the user or the password is incorrect, it will then try TACACS+. This reverses the desired order. The requirement is to use TACACS+ primarily and fall back to local only if the server is unreachable, not to check local first.
- ✓
aaa authentication login default group tacacs+ local
Why this is correct
This command configures AAA authentication for login using the default method list. It specifies that the TACACS+ group should be tried first, and if the server is unreachable, the local database is used as a fallback. This meets the requirement for fallback authentication. The 'group tacacs+' keyword refers to the TACACS+ servers defined with the 'tacacs server' command.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
EIGRP: Basics and Advanced Configuration
Key term
Cisco ISE
Cisco Identity Services Engine is a security policy management platform that controls who can access a network and what they can do once connected.
Key term
AAA on Cisco Devices
AAA on Cisco devices is a security framework that controls who can access the network, what they can do, and keeps a record of their actions.
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.