mediumMultiple Choice
350-401 Practice Question: Runs the following command on Router R1: R1# show…
A network engineer runs the following command on Router R1:
R1# show aaa sessions
Total sessions since last reset: 10
Session Id: 5 Unique Id: 5 User Name: admin
IP Address: 192.168.1.100
Idle Time: 0:00:05 Timeout: 0:10:00 Type: SSH Method: local
Session Id: 6 Unique Id: 6 User Name: neteng
IP Address: 10.0.0.2
Idle Time: 0:02:30 Timeout: 0:10:00 Type: SSH Method: tacacs+
Based on this output, what can be concluded?
⚠ Common exam trap
Cisco often tests the distinction between authentication methods shown in the 'Method' field of 'show aaa sessions', where candidates may incorrectly assume all sessions use the same method or misinterpret idle timeout as an immediate disconnection trigger.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Session 5 is authenticated locally.
The output shows that Session 5 has 'Method: local', which means the user 'admin' was authenticated using the local database on the router, not an external AAA server. Session 6 uses 'Method: tacacs+', confirming TACACS+ authentication for that session. Therefore, only Session 5 is authenticated locally, making option B correct.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Both sessions are authenticated using TACACS+.
Why it's wrong here
This statement is incorrect because session 5 explicitly shows a Method of 'local', meaning the device authenticated that user against its own local username/password database rather than querying a TACACS+ server. TACACS+ is an external AAA protocol that requires communication with a TACACS+ server over TCP port 49; if it were used for both sessions, the Method column would show 'TACACS+' for both. Only session 6 uses TACACS+.
- ✓
Session 5 is authenticated locally.
Why this is correct
The Method field for session 5 reads 'local', which confirms the user was authenticated using the device's local user database, typically configured with 'username' global commands or in the local AAA configuration. Local authentication is commonly used as a fallback method or for console access, and it does not involve any external AAA server. The device compared the supplied credentials directly against its stored username and password hashes, and on success, established the session.
- ✗
Session 6 will be disconnected due to idle timeout.
Why it's wrong here
The idle timeout parameter specifies the maximum period of inactivity allowed before a session is forcibly terminated. Session 6's idle time is 02:30 (2 minutes 30 seconds), which is still substantially below the configured timeout of 10:00 (10 minutes). As a result, the session is not yet at risk of disconnection; only after the idle time exceeds the timeout, or an absolute timeout is reached, would the device terminate the line.
- ✗
Both sessions are using RADIUS for authentication.
Why it's wrong here
This assertion is false because the Method column explicitly lists 'local' for session 5 and 'TACACS+' for session 6, neither of which is RADIUS. RADIUS is a UDP-based AAA protocol (typically ports 1812/1813) that would appear as 'radius' in the output. Since the session output shows two distinct authentication mechanisms, the claim that both use RADIUS directly contradicts the device's recorded method.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 350-401 question from scratch — 1,923 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 350-401 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 350-401 exam.