mediumMultiple Choice
350-401 Practice Question: Consider this AAA configuration: aaa new-model…
Consider this AAA configuration:
aaa new-model aaa authentication login default group tacacs+ local aaa authorization exec default group tacacs+ local aaa accounting exec default stop-only group tacacs+
tacacs-server host 10.0.0.1 key SecretKey tacacs-server host 10.0.0.2 key SecretKey
What is the effect of the accounting command?
⚠ Common exam trap
Cisco often tests the distinction between `start-stop` and `stop-only` keywords in accounting commands, and the trap here is that candidates mistakenly assume `stop-only` means accounting is disabled or that it still sends a start record, when in fact it explicitly omits the start record.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Accounting records are sent to TACACS+ only when the exec session ends.
The `aaa accounting exec default stop-only group tacacs+` command configures TACACS+ accounting to send records only when an exec session ends. The `stop-only` keyword explicitly instructs the device to generate a single accounting record at session termination, not at session start. This is a standard TACACS+ accounting feature used to minimize network overhead while still capturing session duration and resource usage.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Accounting records are sent to TACACS+ only when the exec session ends.
Why this is correct
The `aaa accounting exec default stop-only group tacacs+` command instructs the router to generate a TACACS+ stop accounting record only when the EXEC session ends. This record contains cumulative data like session duration, input/output bytes, and the reason the session closed, and it is sent to the TACACS+ server at that moment. There is no start record transmitted at session initiation, which matches the 'stop-only' behavior.
- ✗
Accounting records are sent to TACACS+ at both session start and end.
Why it's wrong here
If the administrator had used the `start-stop` keyword, the router would send an accounting start record when the EXEC session begins and a stop record when it ends. However, the configuration shown uses `stop-only`, which explicitly suppresses the start record and sends only the stop record. Therefore, this option mischaracterizes the configured behavior.
- ✗
Accounting records are sent to TACACS+ only at session start.
Why it's wrong here
The `stop-only` keyword means no start record is sent at the beginning of the EXEC session; only a stop record is transmitted at termination. Because the router never sends a start record, claiming that records are sent only at session start is the exact opposite of the configured behavior. This option would only describe a hypothetical (and nonstandard) 'start-only' configuration, not the command in question.
- ✗
Accounting is disabled because the command uses 'stop-only' incorrectly.
Why it's wrong here
The `stop-only` syntax is a valid and recognized keyword for the `aaa accounting exec` command in Cisco IOS. It does not disable accounting; rather, it defines that only the stop accounting record is produced. The command is correctly formed and fully functional, so accounting is enabled — just with a limited set of records.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
EIGRP: Basics and Advanced Configuration
Key term
Cisco ISE
Cisco Identity Services Engine is a security policy management platform that controls who can access a network and what they can do once connected.
Key term
AAA on Cisco Devices
AAA on Cisco devices is a security framework that controls who can access the network, what they can do, and keeps a record of their actions.
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.