Courseiva
mediumMultiple Choice

350-401 Practice Question: Examine the following AAA configuration snippet:…

Examine the following AAA configuration snippet:

aaa new-model
aaa authentication login default local
aaa authentication login CONSOLE local
aaa authorization exec default local
aaa accounting exec default start-stop group tacacs+
line con 0

login authentication CONSOLE

line vty 0 4

login authentication default

What is the effect of this configuration?

⚠ Common exam trap

Cisco often tests the distinction between named and default AAA method lists, and the trap here is assuming that 'aaa authentication login default local' applies to all lines uniformly, when in fact a named list applied to a specific line (like 'CONSOLE' on console) overrides the default for that line.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Console login uses local authentication; VTY login uses local authentication; exec accounting is sent to TACACS+.

The configuration defines two AAA authentication login lists: 'default' and 'CONSOLE'. Both lists use the 'local' method, meaning they authenticate against the local user database. The 'aaa authorization exec default local' command enables local authorization for exec sessions, and 'aaa accounting exec default start-stop group tacacs+' sends accounting records for exec sessions to the TACACS+ server. The 'line con 0' applies the 'CONSOLE' list, and 'line vty 0 4' applies the 'default' list, so both use local authentication. Therefore, option A is correct.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Console login uses local authentication; VTY login uses local authentication; exec accounting is sent to TACACS+.

    Why this is correct

    The exhibit's AAA configuration binds a named method list, CONSOLE, to the console line, and that list contains only the keyword 'local', so console logins check the local user database. VTY lines are not bound to any custom list, so they inherit the default method list, which also specifies local authentication. For accounting, the command `exec accounting start-stop tacacs+` is globally configured, meaning each EXEC session's start and stop are recorded and sent to the TACACS+ server. Therefore, authentication remains local for both access types, but accounting traffic is forwarded to TACACS+.

  • ✗

    Console login uses TACACS+ authentication; VTY login uses local authentication; exec accounting is disabled.

    Why it's wrong here

    This answer incorrectly claims the console port authenticates via TACACS+, but the console line is explicitly attached to the CONSOLE method list, which uses 'local' as its only method, so no TACACS+ authentication is attempted for console access. The VTY half is correct because the default list authenticates locally, yet the accounting assertion is false: the configuration globally enables `exec accounting start-stop tacacs+`, so accounting records are definitely sent to TACACS+ rather than disabled. Because two of the three statements are wrong, this option is invalid.

  • ✗

    Both console and VTY login use TACACS+ authentication; exec accounting is sent to TACACS+.

    Why it's wrong here

    This option overstates the role of TACACS+ by claiming both console and VTY authentication use it, but neither method list contains 'group tacacs+'; the CONSOLE list and the default list both specify only 'local', meaning the local username/password database is the sole authentication source for both line types. The only accurate assertion is the final one: the `exec accounting start-stop tacacs+` command is configured, so accounting records are indeed forwarded to the TACACS+ server. However, since the entire authentication half is false, this answer is incorrect.

  • ✗

    Console login uses local authentication; VTY login uses TACACS+ authentication; accounting is not configured.

    Why it's wrong here

    Although this option correctly identifies the console as using local authentication, it fails on the VTY claim: VTY lines are not assigned a TACACS+ method list, but rather inherit the default method list, which has 'local' as its only authentication method. The final clause is also incorrect because accounting is not missing—the global AAA configuration explicitly defines `exec accounting start-stop tacacs+`, which sends EXEC session start/stop records to the TACACS+ server. With two of the three assertions being false, this answer cannot be correct.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.