easyMultiple Choice
350-401 Practice Question: The purpose of the 'aaa authorization exec…
What is the purpose of the 'aaa authorization exec default local' command?
⚠ Common exam trap
Cisco often tests the distinction between authentication, authorization, and accounting; the trap here is confusing 'authorization' with 'authentication', leading candidates to pick Option A because they think the command is about verifying who the user is, rather than what they are allowed to do.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It authorizes exec sessions using the local database, determining if a user can start a shell and their privilege level.
The 'aaa authorization exec default local' command is used to authorize EXEC sessions (user shell access) by checking the local database on the device. It determines whether a user is permitted to start a shell and what privilege level they should receive, based on the local user account configuration. This is distinct from authentication, which verifies identity, and accounting, which logs actions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It authenticates users for exec access using the local database.
Why it's wrong here
This command belongs to authorization, not authentication. Authentication for exec access is configured with 'aaa authentication login default ...', which verifies the username and password before the user can enter the exec shell. 'aaa authorization exec' occurs after authentication and decides whether the user is allowed to start that shell at all. Thus, mixing up the two AAA processes means misattributing the command's purpose.
- ✓
It authorizes exec sessions using the local database, determining if a user can start a shell and their privilege level.
Why this is correct
The 'aaa authorization exec default local' command configures authorization for exec (shell) sessions using the local user database. When a user is authenticated, this level of authorization checks the locally configured 'username' entry, including its 'privilege' attribute, to determine whether the user may start an exec shell and at what privilege level (1-15) they will operate.
- ✗
It enables accounting for exec commands to the local database.
Why it's wrong here
Accounting is a distinct AAA function, not configured with authorization commands. To track exec sessions, you use 'aaa accounting exec default start-stop ...', which sends system accounting records to a remote server (or can be configured for local logging). 'aaa authorization exec' merely checks permissions; it does not create accounting events, and the local database is not an accounting target for this command.
- ✗
It sets the privilege level for all users to 15.
Why it's wrong here
This command does not set a privilege level for users. It specifies the authorization method ('local') that the device will use to determine permitted privileges. The actual privilege level for a specific user is assigned by the user's configuration in the local database (e.g., 'username admin privilege 15') or by an AAA server policy. Without such an assignment, the user may not even be permitted to start an exec shell.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.