easyMultiple Choice
350-401 Practice Question: The default port used by TACACS+ for…
What is the default port used by TACACS+ for communication?
⚠ Common exam trap
Cisco often tests the default port for TACACS+ (49) versus RADIUS (1812/1645) to catch candidates who confuse the two protocols, especially since both are used for AAA but operate on different transport layers and ports.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
49
TACACS+ uses TCP port 49 by default for communication between the Network Access Server (NAS) and the TACACS+ server. This port is defined in the TACACS+ protocol specification (RFC 1492) and is the well-known port reserved for the TACACS+ authentication, authorization, and accounting (AAA) service. Unlike RADIUS, which uses UDP, TACACS+ relies on TCP for reliable, connection-oriented transport.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
49
Why this is correct
Port 49 is the IANA-assigned well-known port for TACACS+ (Terminal Access Controller Access-Control System Plus). TACACS+ uses TCP port 49 for reliable, connection-oriented transport, ensuring delivery of control messages between the network device and the AAA server. The Cisco implementation of TACACS+ defaults to TCP port 49, making this the correct answer.
- ✗
1812
Why it's wrong here
Port 1812 is the standard authentication port for RADIUS (Remote Authentication Dial-In User Service), not TACACS+. RADIUS uses UDP, typically with 1812 for authentication and 1813 for accounting, which is connectionless and unacknowledged. If you configure a TACACS+ server on port 1812, the device would attempt a TCP connection and fail because RADIUS expects UDP traffic.
- ✗
1645
Why it's wrong here
Port 1645 is a legacy RADIUS authentication port used in early Cisco and Livingston deployments before IANA allocated 1812. While some older networks still reference 1645 in RADIUS configurations, TACACS+ never uses this port. A TACACS+ client sending to 1645 would use TCP, but the server would be listening for UDP RADIUS, causing a protocol mismatch and connection failure.
- ✗
389
Why it's wrong here
Port 389 is the well-known port for LDAP (Lightweight Directory Access Protocol), used for querying and modifying directory services like Microsoft Active Directory. LDAP can authenticate users against a directory, but it is not an AAA protocol and does not define TACACS+ framing or packet structure. TACACS+ control traffic is not directed to port 389; that port belongs to directory services, not to TACACS+.
Visual reference
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
Spine-Leaf and Software-Defined Network Architectures
Key term
802.1X Authentication
802.1X is a network access control protocol that prevents unauthorized devices from connecting to a wired or wireless network by requiring them to authenticate before gaining access.
Key term
Cisco ISE
Cisco Identity Services Engine is a security policy management platform that controls who can access a network and what they can do once connected.
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.