Courseiva
mediumMultiple Choice

350-401 Practice Question: Given the following configuration: aaa new-model…

Given the following configuration:

aaa new-model
aaa authentication login default group radius local
aaa authorization exec default group radius local
aaa accounting exec default start-stop group radius

radius-server host 192.168.1.100 key Cisco123 radius-server host 192.168.1.101 key Cisco123

Which statement is true about this configuration?

⚠ Common exam trap

Cisco often tests the misconception that 'group radius local' means local authentication is tried first, or that RADIUS servers are only used for authentication, when in fact the order of methods in the list determines the sequence, and the same method list can apply to authentication, authorization, and accounting.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

If the first RADIUS server (192.168.1.100) is unreachable, the second server (192.168.1.101) is tried before falling back to local.

The configuration uses the 'default' method list for login authentication, exec authorization, and exec accounting. The order 'group radius local' means the router first attempts authentication, authorization, and accounting via the RADIUS servers in the order they are configured. If the first RADIUS server (192.168.1.100) is unreachable, the second server (192.168.1.101) is tried before falling back to local authentication. This is because the 'group radius' keyword directs the router to try all configured RADIUS servers in sequence before resorting to the 'local' fallback method.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    If the first RADIUS server (192.168.1.100) is unreachable, the second server (192.168.1.101) is tried before falling back to local.

    Why this is correct

    When a user attempts authentication, the router consults the method list and sends the request to the first configured RADIUS server, 192.168.1.100. Only if that server times out or is unreachable does the router move to the next server in the list, 192.168.1.101, rather than immediately using local authentication. If all RADIUS servers are unavailable or return errors, the router then falls back to the local database as the final method, so the described behavior is correct.

  • ✗

    The RADIUS servers are used for authentication only, not for authorization or accounting.

    Why it's wrong here

    The AAA configuration shown includes separate statements for authentication, authorization, and accounting, all referencing the same RADIUS server group. For example, the 'aaa authorization' and 'aaa accounting' lines direct those functions to use the RADIUS servers, so RADIUS is not limited to authentication only. In fact, the configuration may also include 'aaa authentication login' and 'aaa accounting exec' commands, with 'group radius' listed in each, meaning RADIUS is used for all three AAA processes.

  • ✗

    Local authentication is always attempted first, then RADIUS.

    Why it's wrong here

    This statement misreads the method list order. In the configuration, the method list for login is explicitly defined as 'group radius local', which means the router first sends the request to RADIUS and only falls back to local if RADIUS servers are unreachable or do not provide a response. The order is controlled by the administrator and can be changed, so local authentication is not always attempted first; here RADIUS is always tried before local.

  • ✗

    The RADIUS key is optional; if omitted, the router uses an empty key.

    Why it's wrong here

    The RADIUS key, configured with the 'key' command under the RADIUS server definition, is not optional in practice. Without a shared secret matching the RADIUS server, the router cannot encrypt or authenticate the RADIUS packets, so the server will reject or ignore the requests. The configuration explicitly includes a key, and omitting it would cause authentication to fail entirely rather than reverting to an 'empty key'.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

Go deeper

Related to this question

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.