Courseiva
easyMultiple SelectObjective-mapped

350-401 Practice Question: Which two statements about local AAA and fallback…

Which two statements about local AAA and fallback methods are true? (Choose two.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Local AAA authentication uses the username and password configured in the running configuration.

Local AAA uses the device's local database for authentication. Fallback methods define the order of servers to try. If all servers are unreachable, the local database can be used as a backup. The 'aaa authentication login default local' command uses the local database only. The 'aaa new-model' command enables AAA globally.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Local AAA authentication uses the username and password configured in the running configuration.

    Why this is correct

    Correct because local authentication relies on the username/password stored on the device.

  • The 'aaa authentication login default local' command configures the device to use a RADIUS server first, then fall back to local.

    Why it's wrong here

    Incorrect because this command uses local authentication only; to add fallback, a method list with multiple methods is needed.

  • When using a RADIUS server group, if the primary server fails to respond, the device automatically tries the next server in the group.

    Why this is correct

    Correct because server groups define an ordered list; if a server is unreachable, the next is tried.

  • The 'aaa new-model' command is required only when using TACACS+ servers.

    Why it's wrong here

    Incorrect because 'aaa new-model' is required to enable any AAA functionality, including local, RADIUS, or TACACS+.

  • Fallback to local authentication occurs only if all remote servers explicitly reject the authentication request.

    Why it's wrong here

    Incorrect because fallback occurs when servers are unreachable (timeout), not when they reject (which results in denial).

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1XEAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

Courseiva writes every 350-401 question from scratch — 1,175 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.