mediumMultiple Choice
350-401 Practice Question: A network administrator checks the AAA…
A network administrator checks the AAA configuration on a router:
R1# show running-config | include aaa aaa new-model aaa authentication login default group radius local aaa authentication login console local aaa authorization exec default group tacacs+ local aaa accounting exec default start-stop group radius
Based on this output, what can be concluded?
⚠ Common exam trap
Cisco often tests the distinction between authentication, authorization, and accounting methods, and the trap here is that candidates confuse the method used for one function (e.g., authentication) with another (e.g., authorization or accounting), or assume that 'default' applies uniformly across all AAA functions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
EXEC authorization uses TACACS+ as the primary method.
The command 'aaa authorization exec default group tacacs+ local' specifies that TACACS+ is the primary method for EXEC authorization, with local as a fallback. This means the router first attempts to authorize EXEC access via TACACS+; if the TACACS+ server does not respond, it falls back to local authentication.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Console login uses RADIUS authentication.
Why it's wrong here
The console line is bound to the method list 'console', explicitly defined by 'aaa authentication login console local'. This uses only the local username database for console authentication, with no RADIUS involvement. The presence of a global RADIUS server group does not affect console login because this method list overrides any default, making the statement false.
- ✓
EXEC authorization uses TACACS+ as the primary method.
Why this is correct
The command 'aaa authorization exec default group tacacs+ local' creates a default EXEC authorization list applied to all EXEC sessions. When a user attempts to start a privileged EXEC shell, the device first sends an authorization request to the TACACS+ server group; only if that server is unavailable or returns no response does it fall back to the local database. Because TACACS+ appears first in the list, it is the primary method for EXEC authorization, making this statement correct.
- ✗
Accounting is performed using TACACS+.
Why it's wrong here
Accounting records are not sent to TACACS+; instead, the configuration uses RADIUS for accounting via a separate statement such as 'aaa accounting exec default start-stop group radius'. TACACS+ is configured for EXEC authorization only (and possibly for login authentication), but no accounting method list references TACACS+ in this setup. Therefore, claiming accounting is performed using TACACS+ is incorrect.
- ✗
Local authentication is never used.
Why it's wrong here
Local authentication is used in multiple places: the console login method list is entirely local, and both the default login method list and the EXEC authorization list include local as a fallback. If TACACS+ or RADIUS servers become unreachable, local usernames still permit console access and provide a fallback for other sessions. Far from never being used, local authentication is a critical safety net, so this statement is false.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
Network Access Control and AAA
Key term
RADIUS vs TACACS+
RADIUS and TACACS+ are two network protocols used to verify user identities and control access to network devices and services, with different approaches to security and flexibility.
Key term
Cisco ISE
Cisco Identity Services Engine is a security policy management platform that controls who can access a network and what they can do once connected.
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
4 more ways this is tested on 350-401
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A network administrator runs the following command on a switch: Switch# show aaa method-list Method List Name: default Type: authentication Group: radius Group: local Method List Name: console Type: authentication Group: local Method List Name: default Type: authorization Group: tacacs+ Group: local Based on this output, what can be concluded?
medium- A.Authorization for all users uses RADIUS.
- B.Console authentication uses RADIUS as fallback.
- ✓ C.RADIUS is the primary authentication method for default login.
- D.TACACS+ is used for authentication.
Why C: The output shows that the default method list for authentication uses RADIUS as the first method and local as the fallback. Since 'default' applies to all lines and services that do not have a named list, RADIUS is the primary authentication method for default login. Option C correctly identifies this primary role of RADIUS.
Variation 2. Consider this AAA configuration: aaa new-model aaa authentication login default local aaa authorization exec default local aaa accounting exec default start-stop group tacacs+ tacacs-server host 10.0.0.1 key SecretKey line con 0 login authentication default line vty 0 4 login authentication default What is the effect of this configuration?
medium- ✓ A.All login attempts use local authentication; exec accounting is sent to TACACS+.
- B.All login attempts use TACACS+ authentication; exec accounting is local.
- C.Console login uses TACACS+; VTY login uses local; accounting is sent to TACACS+.
- D.Authentication and authorization are both performed by TACACS+; accounting is local.
Why A: The configuration sets AAA authentication login to use the local user database (via 'aaa authentication login default local'), so all login attempts (console and VTY) authenticate against the local device. Authorization for exec sessions is also set to local ('aaa authorization exec default local'), meaning no external authorization is used. Accounting for exec sessions is configured with 'start-stop' and points to the TACACS+ server at 10.0.0.1, so all exec session start and stop records are sent to TACACS+. This matches option A.
Variation 3. Examine the following AAA configuration snippet: aaa new-model aaa authentication login default local aaa authentication login CONSOLE local aaa authorization exec default local aaa accounting exec default start-stop group tacacs+ line con 0 login authentication CONSOLE line vty 0 4 login authentication default What is the effect of this configuration?
medium- ✓ A.Console login uses local authentication; VTY login uses local authentication; exec accounting is sent to TACACS+.
- B.Console login uses TACACS+ authentication; VTY login uses local authentication; exec accounting is disabled.
- C.Both console and VTY login use TACACS+ authentication; exec accounting is sent to TACACS+.
- D.Console login uses local authentication; VTY login uses TACACS+ authentication; accounting is not configured.
Why A: The configuration defines two AAA authentication login lists: 'default' and 'CONSOLE'. Both lists use the 'local' method, meaning they authenticate against the local user database. The 'aaa authorization exec default local' command enables local authorization for exec sessions, and 'aaa accounting exec default start-stop group tacacs+' sends accounting records for exec sessions to the TACACS+ server. The 'line con 0' applies the 'CONSOLE' list, and 'line vty 0 4' applies the 'default' list, so both use local authentication. Therefore, option A is correct.
Variation 4. Given the following configuration: aaa new-model aaa authentication login default group radius local aaa authorization exec default group radius local aaa accounting exec default start-stop group radius radius-server host 192.168.1.100 key Cisco123 radius-server host 192.168.1.101 key Cisco123 Which statement is true about this configuration?
medium- ✓ A.If the first RADIUS server (192.168.1.100) is unreachable, the second server (192.168.1.101) is tried before falling back to local.
- B.The RADIUS servers are used for authentication only, not for authorization or accounting.
- C.Local authentication is always attempted first, then RADIUS.
- D.The RADIUS key is optional; if omitted, the router uses an empty key.
Why A: The configuration uses the 'default' method list for login authentication, exec authorization, and exec accounting. The order 'group radius local' means the router first attempts authentication, authorization, and accounting via the RADIUS servers in the order they are configured. If the first RADIUS server (192.168.1.100) is unreachable, the second server (192.168.1.101) is tried before falling back to local authentication. This is because the 'group radius' keyword directs the router to try all configured RADIUS servers in sequence before resorting to the 'local' fallback method.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.