Courseiva
mediumMultiple Select

350-401 Practice Question: Which three statements about RADIUS server…

Which three statements about RADIUS server configuration and operation are true? (Choose three.)

⚠ Common exam trap

A common mix-up: candidates confuse RADIUS with TACACS+ (which uses TCP) and mixing up the legacy ports 1645/1646 with the standard 1812/1813, leading candidates to select incorrect options about transport protocol and default ports.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The default UDP port for RADIUS authentication is 1812.

Option A is correct because RADIUS authentication uses UDP port 1812 by default (with 1813 for accounting), as defined in RFC 2865/2866. Option B is correct because the shared secret is a pre-shared key used to encrypt and authenticate RADIUS messages, so the value configured on the Cisco device (via the 'radius-server key' or per-host 'key') must exactly match the value on the RADIUS server or authentication will fail. Option C is correct because the 'radius-server host' command supports an optional 'key' parameter, allowing a per-server shared secret to be specified, e.g., 'radius-server host 10.1.1.1 key MySecret'. Option D is incorrect because RADIUS uses UDP, not TCP, for transport. Option E is incorrect because the legacy port 1645 is not the default; the standard default authentication port is 1812 (1645 was used by some early implementations but is not the default).

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The default UDP port for RADIUS authentication is 1812.

    Why this is correct

    RADIUS authentication traditionally used UDP 1645, but RFC 2865 reassigned it to UDP 1812, with accounting on 1813. Cisco devices default to 1812 for authentication, making this the standard port for access-request and access-challenge exchanges.

  • ✓

    The shared secret configured on the Cisco device must match the shared secret on the RADIUS server.

    Why this is correct

    RADIUS authenticates access requests using a shared secret that both the network access device and the RADIUS server use to sign and verify packets. If the secrets differ, the server silently discards requests, so matching values on both ends is mandatory for successful authentication.

  • ✓

    The 'radius-server host' command can include an optional 'key' parameter to specify the shared secret.

    Why this is correct

    The radius-server host command accepts an optional key argument, letting you define the shared secret per server directly on the command line rather than relying solely on the global radius-server key. This per-host secret authenticates communication between the router and that specific RADIUS server.

  • ✗

    RADIUS uses TCP to ensure reliable delivery of authentication packets.

    Why it's wrong here

    RADIUS runs over UDP, not TCP, so reliable delivery is not guaranteed by the transport. TCP is used by TACACS+, which is why this is tempting; RADIUS relies on application-layer retransmission and timeouts instead, making this statement false.

  • ✗

    If no port is specified, RADIUS uses port 1645 for authentication by default.

    Why it's wrong here

    RADIUS authentication defaults to UDP port 1812, with 1645 only a legacy value; 1813 is accounting. Specifying 1645 as the default is therefore incorrect, though the older port is still seen in legacy deployments, which makes the statement tempting.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

Go deeper

Related to this question

About these practice questions

One of 1,923 original 350-401 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.