hardMultiple Choice
350-401 Practice Question: Is configuring a Cisco router to use TACACS+ for…
A network engineer is configuring a Cisco router to use TACACS+ for command authorization. The engineer configures 'aaa authorization commands 15 default group tacacs+ local'. When a user with privilege level 15 tries to execute the 'reload' command, the router sends an authorization request to the TACACS+ server. The server responds with an 'Access-Accept' but the command is still denied. The engineer checks the router's configuration and sees that 'aaa accounting commands 15 default start-stop group tacacs+' is also configured. What could be the issue?
⚠ Common exam trap
Cisco often tests the misconception that an 'Access-Accept' response universally permits all actions, when in fact TACACS+ authorization requires explicit attributes for each command or service.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The TACACS+ server's 'Access-Accept' response does not include the necessary authorization attributes to permit the 'reload' command, so the router denies it.
The TACACS+ 'Access-Accept' response must include the specific command (e.g., 'reload') in an authorization attribute (like 'cmd=reload') for the router to permit it. Without these attributes, the router treats the response as a denial, even though the authentication succeeded. The 'local' fallback in the authorization command only applies if the TACACS+ server is unreachable, not when it responds without the required attributes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The TACACS+ server's 'Access-Accept' response does not include the necessary authorization attributes to permit the 'reload' command, so the router denies it.
Why this is correct
In TACACS+, authentication and authorization are separate phases. An Access-Accept only confirms the user's identity; command authorization requires the server to explicitly send an authorization response with attributes such as 'permit' or the specific command (e.g., 'cmd=reload') to allow execution. Without any permitting AV pair, the router's authorization policy defaults to deny, so the 'reload' command is blocked despite a successful authentication.
- ✗
The 'aaa accounting commands 15' command is causing the router to send accounting records before authorization, which delays the response and causes a timeout.
Why it's wrong here
AAA accounting is an independent audit function that tracks what commands were executed after they are authorized and performed. It does not intercept or delay the authorization process; the router sends accounting records asynchronously, not before authorization. Therefore, the 'aaa accounting commands 15' directive cannot cause a timeout or prevent authorization—the failure is due to the TACACS+ authorization response lacking the required permit attributes.
- ✗
The router's 'aaa authorization commands 15' should use 'group tacacs+' without 'local' to ensure only TACACS+ is used.
Why it's wrong here
The 'local' fallback in 'aaa authorization commands 15 group tacacs+ local' is only used when the TACACS+ server is unreachable or does not respond. Since the scenario states the TACACS+ server responded with an Access-Accept (i.e., it is reachable), the local method is never tried. The actual problem is not the fallback order but that the server's authorization reply omitted the necessary permit attributes for the 'reload' command.
- ✗
The user's privilege level on the router is not actually 15, despite the configuration.
Why it's wrong here
Incorrect because the scenario states the user has privilege level 15, and the authorization command is for level 15; if the user were at a lower level, the command would not be subject to that authorization list.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.