easyMultiple Choice
350-401 Practice Question: Is configuring a Cisco router for AAA using a…
A network engineer is configuring a Cisco router for AAA using a RADIUS server. The engineer wants to ensure that if the RADIUS server is unreachable, the router falls back to local authentication for console access. The engineer configures 'aaa authentication login default group radius local' and 'aaa authentication login CONSOLE local'. The console line is configured with 'login authentication CONSOLE'. However, when the RADIUS server is down, the engineer cannot log in via the console. What is the problem?
⚠ Common exam trap
Cisco often tests the nuance that a named authentication list completely replaces the default list for that line, so candidates mistakenly think the default list's fallback logic still applies when the named list's method fails.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The router has no local usernames configured, so the 'local' method has no users to authenticate against.
The 'aaa authentication login CONSOLE local' command tells the router to use only local authentication for the CONSOLE list. When the RADIUS server is down, the console login fails because no local usernames have been configured, so there are no credentials to authenticate against. The fallback to local authentication in the default list is irrelevant because the console line explicitly uses the CONSOLE list, which does not include RADIUS.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The router has no local usernames configured, so the 'local' method has no users to authenticate against.
Why this is correct
The 'local' method in an AAA login method list instructs the router to check credentials against the locally defined username database (created with the 'username' command). If the router has no usernames configured, there are zero valid usernames/passwords to authenticate against, so the login attempt fails immediately. This is true regardless of the method list name or whether aaa new-model is enabled. Thus the correct root cause is the empty local user database.
- ✗
The 'aaa authentication login CONSOLE local' command should be 'aaa authentication login CONSOLE group radius local' to include RADIUS as a fallback.
Why it's wrong here
This option misdiagnoses the failure. The command 'aaa authentication login CONSOLE local' is correctly configured to force console access to use only local authentication; the engineer intentionally avoids RADIUS dependence for out-of-band access. Replacing it with 'group radius local' would cause the router to contact the RADIUS server first, and if RADIUS is unreachable it would then fall back to the local database, which is still empty. Therefore this change would not solve the immediate authentication failure and would alter the intended authentication behavior.
- ✗
The console line should use the default authentication list instead of a named list.
Why it's wrong here
Using a named authentication list is perfectly valid; the 'login authentication CONSOLE' command on the line simply points to the method list called 'CONSOLE'. The default list is only a method list that is used when no named list is explicitly applied, and it would behave identically if it also contained 'local'. The problem is not the list-name indirection; it is that neither the named list nor the default list has any users to check because the local database is empty.
- ✗
The 'aaa new-model' command is missing, so AAA is not enabled.
Why it's wrong here
If 'aaa new-model' were not enabled, the router would reject 'aaa authentication login CONSOLE local' with an unrecognized command error, because AAA commands require new-model to be active. The engineer's successful configuration of the AAA command proves that 'aaa new-model' is present. Additionally, the absence of new-model would cause authentication to fall back to line password or no authentication, not a failure to authenticate against an empty local database. So this option is not the cause of the observed login failure.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
SDN Controllers and Cisco ACI
Key term
AAA on Cisco Devices
AAA on Cisco devices is a security framework that controls who can access the network, what they can do, and keeps a record of their actions.
Key term
Cisco ISE
Cisco Identity Services Engine is a security policy management platform that controls who can access a network and what they can do once connected.
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.