Courseiva
mediumMultiple Select

350-401 Practice Question: Which two statements about AAA authentication…

Which two statements about AAA authentication methods are true? (Choose two.)

⚠ Common exam trap

350-401 often tests the specific password each method uses; candidates may confuse the 'local' method with the enable password or the 'line' method with the enable secret.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The enable method for authentication uses the enable password or secret.

Option B is correct because the AAA 'enable' authentication method prompts for the enable password (configured with 'enable password') or the enable secret (configured with 'enable secret'), which is exactly what this method is designed to verify. Option D is correct because the 'login local' method authenticates users against the local username/password database created with the 'username' command, rather than against a remote AAA server. Option A is wrong because the 'local' method uses the local username database, not the enable password, for authentication. Option C is wrong because the 'none' method performs no authentication at all and does not fall back to the local database. Option E is wrong because the line password method uses the line password configured with the 'password' command under 'line con/vty', not the enable secret.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The local method for authentication uses the enable password for privilege level 15 access.

    Why it's wrong here

    The local method checks the local username/password database, not the enable password. The enable password guards privileged EXEC mode; local authentication instead compares against configured usernames and their associated secrets, so this statement misstates which credential store is consulted.

  • ✓

    The enable method for authentication uses the enable password or secret.

    Why this is correct

    The enable authentication method verifies the user against the locally configured enable password or enable secret before granting privileged EXEC mode. It is a distinct method from login authentication, which validates via line, local, or AAA credentials.

  • ✗

    The none method for authentication provides fallback to the local database if the server is unreachable.

    Why it's wrong here

    The none method permits access without any authentication, granting entry unconditionally rather than falling back to the local database. Fallback to local credentials is provided by listing local after a server group in the method list, not by the none keyword.

  • ✓

    The login local method authenticates users against the local username database.

    Why this is correct

    The login local method checks credentials against the router's own username/password database configured with the username command, rather than querying an external AAA server such as TACACS+ or RADIUS. This satisfies the stem's requirement for an authentication method that validates users locally on the device.

  • ✗

    The line password method for authentication uses the enable secret password.

    Why it's wrong here

    The line password method validates the password set on the console or VTY line itself, not the enable secret. The enable secret protects privileged EXEC mode; line authentication uses the line password configured under line configuration mode.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.