hardMultiple Choice
350-401 Practice Question: A network administrator runs the following debug…
A network administrator runs the following debug on a router:
R1# debug aaa authorization *Mar 1 00:02:45.678: AAA/AUTHOR/EXEC(00000002): Processing author request for user 'jdoe' *Mar 1 00:02:45.678: AAA/AUTHOR/EXEC(00000002): Method=TACACS+ *Mar 1 00:02:45.678: AAA/AUTHOR/EXEC(00000002): TACACS+ server 10.1.1.10:49, timeout 5 *Mar 1 00:02:45.678: AAA/AUTHOR/EXEC(00000002): Sent author request *Mar 1 00:02:45.678: AAA/AUTHOR/EXEC(00000002): Received PASS response *Mar 1 00:02:45.678: AAA/AUTHOR/EXEC(00000002): Pass
Based on this output, what can be concluded?
⚠ Common exam trap
Cisco often tests the distinction between authentication and authorization; the trap here is that candidates see 'authorization' and assume a PASS response means authentication succeeded, but the debug is specifically for authorization, and a PASS response only confirms authorization was granted, not that authentication occurred (though in practice, authorization typically follows authentication).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The TACACS+ server authorized the user successfully.
The debug output shows a 'Received PASS response' from the TACACS+ server at 10.1.1.10:49, followed by 'Pass'. This indicates that the TACACS+ authorization request for user 'jdoe' was successful. TACACS+ encrypts the entire packet and separates authentication, authorization, and accounting (AAA), allowing granular authorization control.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The user jdoe failed authorization.
Why it's wrong here
The debug output explicitly displays a PASS response from the TACACS+ server for the authorization request of user jdoe. A PASS message indicates that the server approved the user's authorization, meaning the user was granted the requested access. Therefore, stating that the user failed authorization directly contradicts the captured debug evidence.
- ✗
Authorization was performed using RADIUS.
Why it's wrong here
The debug output clearly identifies the protocol as TACACS+, not RADIUS. TACACS+ uses TCP and encrypts the entire packet body, while RADIUS uses UDP and encrypts only the password. The presence of TACACS+-specific attributes and the selected method in the debugging session confirm that RADIUS was not used for this authorization.
- ✓
The TACACS+ server authorized the user successfully.
Why this is correct
The TACACS+ server responded with a PASS result for the authorization request, which signifies that the user jdoe was authorized successfully. In TACACS+, the server sends a set of AV-pairs along with the PASS result, defining the user's permitted commands or services. This output confirms that the server granted the user the requested authorization.
- ✗
The user was authenticated but not authorized.
Why it's wrong here
The debug output shows that the TACACS+ server returned a PASS response to the authorization request, proving that authorization was both performed and successful. Saying the user was authenticated but not authorized would imply that the authorization phase either failed or was skipped, which is not the case here. The PASS result clearly indicates the user was fully authorized after authentication.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.