mediumMultiple Choice
350-401 Practice Question: Given the following configuration: aaa new-model…
Given the following configuration:
aaa new-model aaa authentication login default group radius local aaa authorization exec default group radius local aaa accounting exec default start-stop group radius
radius-server host 192.168.1.100 key Cisco123 radius-server host 192.168.1.101 key Cisco123
Which statement is true about this configuration?
⚠ Common exam trap
Cisco often tests the misconception that 'group radius local' means local authentication is tried first, or that RADIUS servers are only used for authentication, when in fact the order of methods in the list determines the sequence, and the same method list can apply to authentication, authorization, and accounting.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
If the first RADIUS server (192.168.1.100) is unreachable, the second server (192.168.1.101) is tried before falling back to local.
The configuration uses the 'default' method list for login authentication, exec authorization, and exec accounting. The order 'group radius local' means the router first attempts authentication, authorization, and accounting via the RADIUS servers in the order they are configured. If the first RADIUS server (192.168.1.100) is unreachable, the second server (192.168.1.101) is tried before falling back to local authentication. This is because the 'group radius' keyword directs the router to try all configured RADIUS servers in sequence before resorting to the 'local' fallback method.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
If the first RADIUS server (192.168.1.100) is unreachable, the second server (192.168.1.101) is tried before falling back to local.
Why this is correct
When a user attempts authentication, the router consults the method list and sends the request to the first configured RADIUS server, 192.168.1.100. Only if that server times out or is unreachable does the router move to the next server in the list, 192.168.1.101, rather than immediately using local authentication. If all RADIUS servers are unavailable or return errors, the router then falls back to the local database as the final method, so the described behavior is correct.
- ✗
The RADIUS servers are used for authentication only, not for authorization or accounting.
Why it's wrong here
The AAA configuration shown includes separate statements for authentication, authorization, and accounting, all referencing the same RADIUS server group. For example, the 'aaa authorization' and 'aaa accounting' lines direct those functions to use the RADIUS servers, so RADIUS is not limited to authentication only. In fact, the configuration may also include 'aaa authentication login' and 'aaa accounting exec' commands, with 'group radius' listed in each, meaning RADIUS is used for all three AAA processes.
- ✗
Local authentication is always attempted first, then RADIUS.
Why it's wrong here
This statement misreads the method list order. In the configuration, the method list for login is explicitly defined as 'group radius local', which means the router first sends the request to RADIUS and only falls back to local if RADIUS servers are unreachable or do not provide a response. The order is controlled by the administrator and can be changed, so local authentication is not always attempted first; here RADIUS is always tried before local.
- ✗
The RADIUS key is optional; if omitted, the router uses an empty key.
Why it's wrong here
The RADIUS key, configured with the 'key' command under the RADIUS server definition, is not optional in practice. Without a shared secret matching the RADIUS server, the router cannot encrypt or authenticate the RADIUS packets, so the server will reject or ignore the requests. The configuration explicitly includes a key, and omitting it would cause authentication to fail entirely rather than reverting to an 'empty key'.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
EIGRP: Basics and Advanced Configuration
Key term
802.1X Authentication
802.1X is a network access control protocol that prevents unauthorized devices from connecting to a wired or wireless network by requiring them to authenticate before gaining access.
Key term
RADIUS vs TACACS+
RADIUS and TACACS+ are two network protocols used to verify user identities and control access to network devices and services, with different approaches to security and flexibility.
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.