mediumMultiple Select
350-401 Practice Question: Which two statements about AAA authentication…
Which two statements about AAA authentication methods are true? (Choose two.)
⚠ Common exam trap
350-401 often tests the specific password each method uses; candidates may confuse the 'local' method with the enable password or the 'line' method with the enable secret.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The enable method for authentication uses the enable password or secret.
Option B is correct because the AAA 'enable' authentication method prompts for the enable password (configured with 'enable password') or the enable secret (configured with 'enable secret'), which is exactly what this method is designed to verify. Option D is correct because the 'login local' method authenticates users against the local username/password database created with the 'username' command, rather than against a remote AAA server. Option A is wrong because the 'local' method uses the local username database, not the enable password, for authentication. Option C is wrong because the 'none' method performs no authentication at all and does not fall back to the local database. Option E is wrong because the line password method uses the line password configured with the 'password' command under 'line con/vty', not the enable secret.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The local method for authentication uses the enable password for privilege level 15 access.
Why it's wrong here
The local method checks the local username/password database, not the enable password. The enable password guards privileged EXEC mode; local authentication instead compares against configured usernames and their associated secrets, so this statement misstates which credential store is consulted.
- ✓
The enable method for authentication uses the enable password or secret.
Why this is correct
The enable authentication method verifies the user against the locally configured enable password or enable secret before granting privileged EXEC mode. It is a distinct method from login authentication, which validates via line, local, or AAA credentials.
- ✗
The none method for authentication provides fallback to the local database if the server is unreachable.
Why it's wrong here
The none method permits access without any authentication, granting entry unconditionally rather than falling back to the local database. Fallback to local credentials is provided by listing local after a server group in the method list, not by the none keyword.
- ✓
The login local method authenticates users against the local username database.
Why this is correct
The login local method checks credentials against the router's own username/password database configured with the username command, rather than querying an external AAA server such as TACACS+ or RADIUS. This satisfies the stem's requirement for an authentication method that validates users locally on the device.
- ✗
The line password method for authentication uses the enable secret password.
Why it's wrong here
The line password method validates the password set on the console or VTY line itself, not the enable secret. The enable secret protects privileged EXEC mode; line authentication uses the line password configured under line configuration mode.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Key term
AAA on Cisco Devices
AAA on Cisco devices is a security framework that controls who can access the network, what they can do, and keeps a record of their actions.
Key term
Cisco ISE
Cisco Identity Services Engine is a security policy management platform that controls who can access a network and what they can do once connected.
About these practice questions
This 350-401 question is part of Courseiva's 1,923-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.