Courseiva
hardMultiple Choice

350-401 Practice Question: Runs the following debug on a router: R1# debug…

A network engineer runs the following debug on a router:

R1# debug aaa authentication

*Mar  1 00:01:23.456: AAA/BIND(00000001): Bind iplist
*Mar  1 00:01:23.456: AAA/AUTHEN/LOGIN (00000001): Pick method list 'default'
*Mar  1 00:01:23.456: AAA/AUTHEN/LOGIN (00000001): Method=RADIUS
*Mar  1 00:01:23.456: AAA/AUTHEN/LOGIN (00000001): RADIUS server 10.1.1.10:1812, timeout 5, retransmit 2
*Mar  1 00:01:23.456: AAA/AUTHEN/LOGIN (00000001): Sent username 'admin', password ****
*Mar  1 00:01:23.456: AAA/AUTHEN/LOGIN (00000001): Received PASS response
*Mar  1 00:01:23.456: AAA/AUTHEN/LOGIN (00000001): Pass

Based on this output, what can be concluded?

⚠ Common exam trap

Cisco often tests the distinction between RADIUS and TACACS+ by including port numbers or method names in debug output, and the trap here is that candidates may assume 'PASS response' could mean local authentication or fail to notice the RADIUS-specific port 1812.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The RADIUS server 10.1.1.10 authenticated the user successfully.

The debug output shows a successful AAA authentication process: the router binds to an IP list, selects the default method list, attempts RADIUS authentication against server 10.1.1.10:1812, sends the username 'admin' with a masked password, and receives a 'PASS response' followed by 'Pass'. This confirms that the RADIUS server authenticated the user successfully, making option C correct.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Authentication failed due to incorrect password.

    Why it's wrong here

    The debug output explicitly records 'Received PASS response' and 'Pass,' which correspond to a RADIUS Access-Accept from the server. If the password were incorrect, the RADIUS server would return an Access-Reject and the router would log something like 'Authentication failed' or 'Fail' instead. Since a PASS response was received, the password was validated successfully, so this option cannot be correct.

  • ✗

    The router used TACACS+ for authentication.

    Why it's wrong here

    The debug output shows the router communicating with a RADIUS server, as indicated by the 'radius' keyword and the server address 10.1.1.10. TACACS+ uses TCP port 49 and an entirely different packet structure, and would be labeled 'tacacs' in the debug logs. Here the authentication type is explicitly RADIUS, which is a UDP-based AAA protocol (typically ports 1812/1645).

  • ✓

    The RADIUS server 10.1.1.10 authenticated the user successfully.

    Why this is correct

    The debug output shows the RADIUS server 10.1.1.10 responding to the authentication request with a PASS response, which is the RADIUS Access-Accept message. This confirms that the server successfully authenticated the user, and the router accepts the session. The output also identifies the username as 'admin' and marks the authentication as successful with 'Pass,' so the correct answer is that the RADIUS server authenticated the user successfully.

  • ✗

    The user 'admin' was authenticated using local database.

    Why it's wrong here

    Local authentication would mean the router checks its own username/password database, and no RADIUS packets would be exchanged with 10.1.1.10. The debug output clearly shows an exchange with the RADIUS server, and the 'PASS response' comes from that server, not from the local database. Therefore, the user 'admin' was authenticated by RADIUS, not by the local database on the router.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.