mediumMultiple Select
350-401 Practice Question: Which three statements about RADIUS server…
Which three statements about RADIUS server configuration and operation are true? (Choose three.)
⚠ Common exam trap
A common mix-up: candidates confuse RADIUS with TACACS+ (which uses TCP) and mixing up the legacy ports 1645/1646 with the standard 1812/1813, leading candidates to select incorrect options about transport protocol and default ports.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The default UDP port for RADIUS authentication is 1812.
Option A is correct because RADIUS authentication uses UDP port 1812 by default (with 1813 for accounting), as defined in RFC 2865/2866. Option B is correct because the shared secret is a pre-shared key used to encrypt and authenticate RADIUS messages, so the value configured on the Cisco device (via the 'radius-server key' or per-host 'key') must exactly match the value on the RADIUS server or authentication will fail. Option C is correct because the 'radius-server host' command supports an optional 'key' parameter, allowing a per-server shared secret to be specified, e.g., 'radius-server host 10.1.1.1 key MySecret'. Option D is incorrect because RADIUS uses UDP, not TCP, for transport. Option E is incorrect because the legacy port 1645 is not the default; the standard default authentication port is 1812 (1645 was used by some early implementations but is not the default).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The default UDP port for RADIUS authentication is 1812.
Why this is correct
RADIUS authentication traditionally used UDP 1645, but RFC 2865 reassigned it to UDP 1812, with accounting on 1813. Cisco devices default to 1812 for authentication, making this the standard port for access-request and access-challenge exchanges.
- ✓
The shared secret configured on the Cisco device must match the shared secret on the RADIUS server.
Why this is correct
RADIUS authenticates access requests using a shared secret that both the network access device and the RADIUS server use to sign and verify packets. If the secrets differ, the server silently discards requests, so matching values on both ends is mandatory for successful authentication.
- ✓
The 'radius-server host' command can include an optional 'key' parameter to specify the shared secret.
Why this is correct
The radius-server host command accepts an optional key argument, letting you define the shared secret per server directly on the command line rather than relying solely on the global radius-server key. This per-host secret authenticates communication between the router and that specific RADIUS server.
- ✗
RADIUS uses TCP to ensure reliable delivery of authentication packets.
Why it's wrong here
RADIUS runs over UDP, not TCP, so reliable delivery is not guaranteed by the transport. TCP is used by TACACS+, which is why this is tempting; RADIUS relies on application-layer retransmission and timeouts instead, making this statement false.
- ✗
If no port is specified, RADIUS uses port 1645 for authentication by default.
Why it's wrong here
RADIUS authentication defaults to UDP port 1812, with 1645 only a legacy value; 1813 is accounting. Specifying 1645 as the default is therefore incorrect, though the older port is still seen in legacy deployments, which makes the statement tempting.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
Spine-Leaf and Software-Defined Network Architectures
Key term
802.1X Authentication
802.1X is a network access control protocol that prevents unauthorized devices from connecting to a wired or wireless network by requiring them to authenticate before gaining access.
Key term
RADIUS vs TACACS+
RADIUS and TACACS+ are two network protocols used to verify user identities and control access to network devices and services, with different approaches to security and flexibility.
About these practice questions
One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.