mediumMultiple SelectObjective-mapped
350-401 Practice Question: Which two statements about AAA authentication…
Which two statements about AAA authentication methods are true? (Choose two.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The enable method for authentication uses the enable password or secret.
Statements B and D are true. The enable method uses the enable password or secret, and the login local method authenticates against the local username database. Statement A is false because the local method uses the local username database, not the enable password. Statement C is false because the none method provides no authentication and has no fallback. Statement E is false because the line password method uses the password configured under the line, not the enable secret.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The local method for authentication uses the enable password for privilege level 15 access.
Why it's wrong here
The local method uses the local username database, not the enable password.
- ✓
The enable method for authentication uses the enable password or secret.
Why this is correct
The enable method uses the enable password or secret for authentication.
- ✗
The none method for authentication provides fallback to the local database if the server is unreachable.
Why it's wrong here
The none method provides no authentication, not a fallback.
- ✓
The login local method authenticates users against the local username database.
Why this is correct
The login local method authenticates using the local username database.
- ✗
The line password method for authentication uses the enable secret password.
Why it's wrong here
The line password method uses the password configured under the line, not the enable secret.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
Network Automation and Programmability
Key term
AAA on Cisco Devices
AAA on Cisco devices is a security framework that controls who can access the network, what they can do, and keeps a record of their actions.
Key term
Cisco ISE
Cisco Identity Services Engine is a security policy management platform that controls who can access a network and what they can do once connected.
About these practice questions
This 350-401 question is part of Courseiva's 1,175-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.