350-401 Security Practice Question
A network engineer configures a Cisco IOS router to authenticate administrative SSH logins against a Cisco ISE server using TACACS+. After applying the configuration, a valid ISE user can log in but receives no privilege level and cannot enter privileged EXEC mode. The relevant configuration is:
aaa new-model aaa authentication login default group tacacs+ local aaa authorization exec default group tacacs+ local
tacacs server ISE address ipv4 10.10.10.50 key Cisco123
Which action most directly resolves the problem?
⚠ Common exam trap
The trap here is assuming that successful TACACS+ authentication automatically carries a privilege level, when privilege assignment actually depends on authorization AV pairs returned by the server.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the ISE TACACS+ device to return the cisco-av-pair shell:priv-lvl=15 attribute for authorized users.
Successful TACACS+ authentication only proves the user's identity; the privilege level comes from authorization AV pairs. Because the router shows the user authenticated but stuck at unprivileged EXEC, the ISE authorization policy must be returning no shell:priv-lvl value. Adding the cisco-av-pair shell:priv-lvl=15 attribute to the matching authorization rule gives the router the privilege level to apply after login.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable AAA accounting with the aaa accounting exec default start-stop group tacacs+ command so ISE records the session.
Why it's wrong here
Accounting only logs session start and stop events for auditing and billing. It has no influence over the privilege level granted to a user during login. Enabling accounting would provide visibility into the sessions but would not change the authorization result, so the user would still land at privilege level 1 and remain unable to enter privileged EXEC mode.
- ✓
Configure the ISE TACACS+ device to return the cisco-av-pair shell:priv-lvl=15 attribute for authorized users.
Why this is correct
TACACS+ authorization for EXEC sessions relies on AV pairs returned by the server. The cisco-av-pair shell:priv-lvl attribute tells the router which privilege level the user receives after authentication. Without it, the AAA client defaults to privilege level 1, so the user cannot enter privileged EXEC mode. Supplying the AV pair in the ISE authorization policy resolves the symptom directly.
- ✗
Add the aaa authorization commands 15 default group tacacs+ local command to the router.
Why it's wrong here
Command authorization controls which individual commands a user may execute once already at a given privilege level. It does not assign the initial privilege level after login. Adding command authorization could even restrict the user further. The reported problem is that the user never reaches privileged EXEC at all, which is governed by EXEC authorization and the privilege-level AV pair.
- ✗
Change the aaa authentication login method list to use the local database before the tacacs+ group.
Why it's wrong here
Reordering the authentication method list would only affect how the router falls back when TACACS+ is unreachable. The user already authenticates successfully against ISE, so the authentication sequence is not the failing component. The missing behavior is privilege-level assignment, which is delivered through authorization AV pairs, not by promoting the local database ahead of the TACACS+ group.
Visual reference
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
SDN Controllers and Cisco ACI
Key term
Cisco ISE
Cisco Identity Services Engine is a security policy management platform that controls who can access a network and what they can do once connected.
Key term
AAA on Cisco Devices
AAA on Cisco devices is a security framework that controls who can access the network, what they can do, and keeps a record of their actions.
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.