mediumMultiple Choice
350-401 Practice Question: Examine this configuration: aaa new-model aaa…
Examine this configuration:
aaa new-model aaa authentication login default local aaa authorization exec default local aaa accounting exec default start-stop group tacacs+ line vty 0 4
login authentication default privilege level 15
What is missing to ensure that VTY users are authenticated via TACACS+?
⚠ Common exam trap
Cisco often tests the distinction between authentication, authorization, and accounting, and the trap here is that candidates see 'group tacacs+' in the accounting or authorization commands and assume authentication is also covered, when in fact each AAA component must be explicitly configured with the desired method list.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The 'aaa authentication login default' command should include 'group tacacs+' before 'local'.
The 'aaa authentication login default local' command specifies that the default login authentication method is local, meaning VTY users are authenticated against the local user database. To authenticate via TACACS+, the command must include 'group tacacs+' before 'local' so that TACACS+ is tried first, with local as a fallback. Without this, TACACS+ is never consulted for authentication, even though authorization and accounting are configured for TACACS+.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The 'aaa authentication login default' command should include 'group tacacs+' before 'local'.
Why this is correct
The default authentication method list must name 'group tacacs+' as the first method because Cisco AAA evaluates method list entries in order and stops at the first success or failure. With only 'local' configured, the router never sends the username and password to the TACACS+ server, so TACACS+ users cannot authenticate. Adding 'group tacacs+' before 'local' still preserves local as a fallback if the TACACS+ server is unreachable, which is exactly the correct fix for this scenario.
- ✗
The 'aaa authorization exec default' command should include 'group tacacs+'.
Why it's wrong here
Authorization exec is a separate AAA phase that runs only after authentication succeeds; its method list determines what privilege level or command permissions the user receives, not whether the login is accepted. Configuring 'group tacacs+' there might allow the TACACS+ server to deliver an exec privilege, but it would not cause the TACACS+ server to validate the user's password. Because the reported failure occurs during authentication, changing the authorization configuration cannot fix the authentication problem.
- ✗
The 'aaa accounting exec default' command should include 'group tacacs+'.
Why it's wrong here
Accounting is a post-login phase that records and reports successful sessions, commands, or resource usage; it has no role in deciding whether an access request is accepted. Adding 'group tacacs+' to the accounting exec default list would only ensure that the TACACS+ server receives accounting records, and even if the server rejected those records, the session would still be established. The absence of accounting can never block authentication, making this option irrelevant to the issue.
- ✗
The 'privilege level 15' command under VTY lines is missing.
Why it's wrong here
The 'privilege level 15' command on the VTY lines is a per-line authorization parameter that controls the user's exec-level access after login; it does not alter how the AAA method lists authenticate a user. If the authentication list remains 'aaa authentication login default local', even a correctly configured privilege level 15 line would still force local database validation and never contact TACACS+. The scenario already states that privilege level is configured, and in any event privilege level has no bearing on which authentication method is selected.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
EIGRP: Basics and Advanced Configuration
Key term
AAA on Cisco Devices
AAA on Cisco devices is a security framework that controls who can access the network, what they can do, and keeps a record of their actions.
Key term
Cisco ISE
Cisco Identity Services Engine is a security policy management platform that controls who can access a network and what they can do once connected.
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.