Courseiva
mediumMultiple Choice

350-401 Practice Question: Examine this configuration: aaa new-model aaa…

Examine this configuration:

aaa new-model
aaa authentication login default local
aaa authorization exec default local
aaa accounting exec default start-stop group tacacs+
line vty 0 4

login authentication default privilege level 15

What is missing to ensure that VTY users are authenticated via TACACS+?

⚠ Common exam trap

Cisco often tests the distinction between authentication, authorization, and accounting, and the trap here is that candidates see 'group tacacs+' in the accounting or authorization commands and assume authentication is also covered, when in fact each AAA component must be explicitly configured with the desired method list.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The 'aaa authentication login default' command should include 'group tacacs+' before 'local'.

The 'aaa authentication login default local' command specifies that the default login authentication method is local, meaning VTY users are authenticated against the local user database. To authenticate via TACACS+, the command must include 'group tacacs+' before 'local' so that TACACS+ is tried first, with local as a fallback. Without this, TACACS+ is never consulted for authentication, even though authorization and accounting are configured for TACACS+.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The 'aaa authentication login default' command should include 'group tacacs+' before 'local'.

    Why this is correct

    The default authentication method list must name 'group tacacs+' as the first method because Cisco AAA evaluates method list entries in order and stops at the first success or failure. With only 'local' configured, the router never sends the username and password to the TACACS+ server, so TACACS+ users cannot authenticate. Adding 'group tacacs+' before 'local' still preserves local as a fallback if the TACACS+ server is unreachable, which is exactly the correct fix for this scenario.

  • ✗

    The 'aaa authorization exec default' command should include 'group tacacs+'.

    Why it's wrong here

    Authorization exec is a separate AAA phase that runs only after authentication succeeds; its method list determines what privilege level or command permissions the user receives, not whether the login is accepted. Configuring 'group tacacs+' there might allow the TACACS+ server to deliver an exec privilege, but it would not cause the TACACS+ server to validate the user's password. Because the reported failure occurs during authentication, changing the authorization configuration cannot fix the authentication problem.

  • ✗

    The 'aaa accounting exec default' command should include 'group tacacs+'.

    Why it's wrong here

    Accounting is a post-login phase that records and reports successful sessions, commands, or resource usage; it has no role in deciding whether an access request is accepted. Adding 'group tacacs+' to the accounting exec default list would only ensure that the TACACS+ server receives accounting records, and even if the server rejected those records, the session would still be established. The absence of accounting can never block authentication, making this option irrelevant to the issue.

  • ✗

    The 'privilege level 15' command under VTY lines is missing.

    Why it's wrong here

    The 'privilege level 15' command on the VTY lines is a per-line authorization parameter that controls the user's exec-level access after login; it does not alter how the AAA method lists authenticate a user. If the authentication list remains 'aaa authentication login default local', even a correctly configured privilege level 15 line would still force local database validation and never contact TACACS+. The scenario already states that privilege level is configured, and in any event privilege level has no bearing on which authentication method is selected.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.