hardMultiple Choice
350-401 Practice Question: An enterprise network uses TACACS+ for device…
An enterprise network uses TACACS+ for device administration and RADIUS for network access (VPN and wireless). The TACACS+ server is configured to authorize commands. A network engineer notices that after a recent upgrade of the TACACS+ server software, some commands that were previously authorized are now being denied. The engineer checks the router configuration and sees 'aaa authorization commands 15 default group tacacs+'. The TACACS+ server logs show that the authorization requests are being sent and responded to. What is the most likely cause?
⚠ Common exam trap
Cisco often tests the distinction between authentication and authorization, and the trap here is that candidates assume a reachability or configuration syntax issue (like missing 'local' or privilege level) rather than understanding that TACACS+ authorization is server-driven and its default behavior can change after an upgrade.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The TACACS+ server upgrade changed the default authorization behavior from permissive to restrictive, requiring explicit 'permit' statements for each command, and the existing rules may not cover all commands.
TACACS+ uses an authorization model where the server explicitly permits or denies each command. After an upgrade, the default behavior may have changed from a permissive mode (allowing commands not explicitly denied) to a restrictive mode (denying commands not explicitly permitted). Since the router is configured to use TACACS+ for command authorization (aaa authorization commands 15 default group tacacs+), and the server logs show requests and responses, the issue is that the server is now denying commands that were previously allowed due to missing explicit permit statements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The router's 'aaa authorization commands 15 default group tacacs+' command is missing the 'local' keyword, so if TACACS+ denies, there is no fallback.
Why it's wrong here
Incorrect because the engineer wants TACACS+ to authorize commands, and the issue is that TACACS+ is responding with a deny, not that the router is failing to fall back. Adding 'local' would not help if TACACS+ explicitly denies.
- ✓
The TACACS+ server upgrade changed the default authorization behavior from permissive to restrictive, requiring explicit 'permit' statements for each command, and the existing rules may not cover all commands.
Why this is correct
The TACACS+ server's command authorization policy is the decisive factor here. When the server was upgraded, the default authorization behavior for commands likely changed from permissive to restrictive, meaning that without explicit 'permit' statements for each command, the server will respond with a denial. The existing rules on the TACACS+ server may not cover all commands that the user is trying to execute, so even though the router correctly forwards authorization requests, the server's deny response blocks the commands. The fix is to update the TACACS+ server's rule set to explicitly permit the required commands at privilege level 15.
- ✗
The router's privilege level 15 is not correctly assigned to the user.
Why it's wrong here
This is not the cause because the user is already operating at privilege level 15, as evidenced by the 'aaa authorization commands 15' statement in the router's configuration. The router's privilege level determines which commands require authorization and what local permissions exist, but in this scenario, the final decision lies with the TACACS+ server, which is explicitly denying the commands. A correct privilege level assignment does not guarantee that TACACS+ will authorize every command; the server's rules are separate and must allow the command regardless of the user's privilege level.
- ✗
The TACACS+ server is not reachable due to a firewall change, causing the router to deny all commands.
Why it's wrong here
The issue is not with reachability because the TACACS+ server logs confirm that it is receiving authorization requests and sending responses back to the router. If a firewall were blocking traffic, the router would not receive responses and would either time out or fall back to a default authorization method, which is not what the logs show. The fact that the server is responding indicates the network path is functional, so the problem must be in the server's authorization policy, not in connectivity.
Visual reference
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
Network Access Control and AAA
Key term
RADIUS vs TACACS+
RADIUS and TACACS+ are two network protocols used to verify user identities and control access to network devices and services, with different approaches to security and flexibility.
Key term
802.1X Authentication
802.1X is a network access control protocol that prevents unauthorized devices from connecting to a wired or wireless network by requiring them to authenticate before gaining access.
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.