Drag and drop the steps of the TACACS+ authentication process into the correct order, from first to last.
Drag steps to the numbered slots on the right, or tap a step then tap a slot.
350-401 · topic practice
Practise ENCOR 350-401 Aaa Radius Tacacs practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.
What the exam tests
Aaa Radius Tacacs questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Practice set
20 questions · select your answer, then reveal the explanation
Drag steps to the numbered slots on the right, or tap a step then tap a slot.
Trap 1: The supplicant is the device that provides authentication services,…
Incorrect; the supplicant is the client requesting access, not the authentication server.
Trap 2: 802.1X is only supported on wireless networks and cannot be used on…
Incorrect; 802.1X is widely used on both wired and wireless networks.
The supplicant communicates with the authenticator using EAP over LAN (EAPoL) frames.
Correct; EAPoL is the encapsulation used for 802.1X on wired LANs.
The authenticator is typically a network switch or wireless access point.
Correct; the authenticator enforces access control and relays EAP messages.
The supplicant is the device that provides authentication services, such as a RADIUS server.
Why wrong: Incorrect; the supplicant is the client requesting access, not the authentication server.
The authentication server is usually a RADIUS server that validates credentials.
Correct; RADIUS is the standard protocol for 802.1X authentication servers.
802.1X is only supported on wireless networks and cannot be used on wired switches.
Why wrong: Incorrect; 802.1X is widely used on both wired and wireless networks.
Drag steps to the numbered slots on the right, or tap a step then tap a slot.
Drag steps to the numbered slots on the right, or tap a step then tap a slot.
Drag steps to the numbered slots on the right, or tap a step then tap a slot.
Supplicant sends EAPoL-Start
EAPoL-Start is the first message sent by the supplicant to begin the 802.1X authentication process.
Authenticator sends EAP-Request/Identity
The authenticator responds to the EAPoL-Start by sending an EAP-Request/Identity to request the supplicant's identity.
Supplicant sends EAP-Response/Identity
The supplicant sends an EAP-Response/Identity containing its identity to the authenticator.
Authenticator forwards EAP-Response to RADIUS
The authenticator encapsulates the EAP-Response/Identity in a RADIUS Access-Request packet and forwards it to the RADIUS server.
RADIUS server sends EAP-Request for client certificate
The RADIUS server sends an EAP-Request for the client certificate, initiating the TLS handshake for mutual authentication.
Drag a concept onto its matching description — or click a concept then click the description.
Initiates an authentication session and contains the username
Sends a challenge (e.g., password prompt) or authentication result
Carries the user's response to a challenge
Indicates successful authentication and may include authorization attributes
Indicates authentication failure
Drag a concept onto its matching description — or click a concept then click the description.
1
4
6
8
22
Drag steps to the numbered slots on the right, or tap a step then tap a slot.
Drag a concept onto its matching description — or click a concept then click the description.
Verifies the identity of a user or device; Typically performed first in the AAA process
Determines what resources or services a user is allowed to access; Can use attributes like privilege level or ACLs
Collects and logs usage data for auditing or billing
Trap 1: The authenticator (switch) performs the actual authentication of…
Incorrect because the authenticator does not authenticate; it relays EAP messages between the supplicant and the RADIUS server, which performs the authentication.
Trap 2: EAPOL frames are used only between the authentication server and…
Incorrect because EAPOL (EAP over LAN) frames are used between the supplicant and the authenticator, not between the authenticator and the RADIUS server (which uses RADIUS protocol).
Trap 3: The authenticator places the port in the unauthorized state before…
Incorrect because the port is initially in the unauthorized state, but this is a default condition, not something the authenticator does 'before authentication completes'—the statement is ambiguous and not a key process step.
The supplicant sends an EAPOL-Start frame to begin the authentication process.
Correct because the supplicant (client) typically initiates 802.1X by sending an EAPOL-Start frame to the authenticator.
The authenticator (switch) performs the actual authentication of the supplicant credentials.
Why wrong: Incorrect because the authenticator does not authenticate; it relays EAP messages between the supplicant and the RADIUS server, which performs the authentication.
The authentication server (RADIUS) sends an EAP-Success message after successful validation of credentials.
Correct because the RADIUS server validates the supplicant's credentials and sends an EAP-Success (or EAP-Failure) to the authenticator, which forwards it to the supplicant.
EAPOL frames are used only between the authentication server and the authenticator.
Why wrong: Incorrect because EAPOL (EAP over LAN) frames are used between the supplicant and the authenticator, not between the authenticator and the RADIUS server (which uses RADIUS protocol).
The authenticator places the port in the unauthorized state before authentication completes.
Why wrong: Incorrect because the port is initially in the unauthorized state, but this is a default condition, not something the authenticator does 'before authentication completes'—the statement is ambiguous and not a key process step.
Drag steps to the numbered slots on the right, or tap a step then tap a slot.
Drag steps to the numbered slots on the right, or tap a step then tap a slot.
Drag a concept onto its matching description — or click a concept then click the description.
RADIUS
TACACS+
RADIUS
TACACS+
RADIUS
Trap 1: MAB requires the supplicant to present a digital certificate for…
Incorrect; MAB uses MAC addresses, not certificates.
Trap 2: MAB encrypts the MAC address using TLS before sending it to the…
Incorrect; MAB sends the MAC address in plaintext within the RADIUS packet.
Trap 3: MAB uses EAPoL to transport the MAC address between the switch and…
Incorrect; MAB does not involve EAPoL; the switch directly sends a RADIUS Access-Request.
MAB is used as a fallback authentication method for devices that do not support 802.1X.
Correct; MAB allows non-802.1X-capable devices to authenticate.
MAB requires the supplicant to present a digital certificate for authentication.
Why wrong: Incorrect; MAB uses MAC addresses, not certificates.
In MAB, the switch sends the MAC address of the endpoint as the username and password to the RADIUS server.
Correct; the MAC address is used as both the username and password in the RADIUS request.
MAB encrypts the MAC address using TLS before sending it to the RADIUS server.
Why wrong: Incorrect; MAB sends the MAC address in plaintext within the RADIUS packet.
MAB uses EAPoL to transport the MAC address between the switch and the endpoint.
Why wrong: Incorrect; MAB does not involve EAPoL; the switch directly sends a RADIUS Access-Request.
Drag a concept onto its matching description — or click a concept then click the description.
Shares context and session data between DNA Center and ISE
Enforces security group tags (SGTs) for micro-segmentation
Provides authentication, authorization, and accounting for network access
Manages guest user portal, sponsor workflows, and captive portal
Identifies endpoint device type and attributes for policy enforcement
Drag a concept onto its matching description — or click a concept then click the description.
Enables real-time context sharing between DNA Center and ISE
Defines and enforces security group access policies across the network
Provides authentication, authorization, and accounting for network access
Carries security group tag information in data packets for policy enforcement
Allows manual configuration of ISE policies and user identity stores
Drag a concept onto its matching description — or click a concept then click the description.
Uses UDP transport; Encrypts only the password in the packet; Combines authentication and authorization into one process
Uses TCP transport; Encrypts the entire packet payload
Drag a concept onto its matching description — or click a concept then click the description.
Verifies the identity of a user or device; Typically uses credentials such as username/password or certificates
Determines what resources or commands a user can access; Can be based on privilege levels or attribute-value pairs
Records user activity for auditing or billing purposes
Trap 1: RADIUS encrypts the entire packet payload for all attributes.
Incorrect because RADIUS only encrypts the password field; other attributes are sent in cleartext.
Trap 2: RADIUS supports per-command authorization for shell sessions.
Incorrect because per-command authorization is a feature of TACACS+, not RADIUS.
RADIUS combines authentication and authorization in a single packet.
Correct because RADIUS merges authentication and authorization in the Access-Accept packet.
TACACS+ uses TCP port 49 by default.
Correct because TACACS+ uses TCP port 49 for reliable delivery.
RADIUS encrypts the entire packet payload for all attributes.
Why wrong: Incorrect because RADIUS only encrypts the password field; other attributes are sent in cleartext.
TACACS+ provides separate authentication, authorization, and accounting processes.
Correct because TACACS+ uses distinct packets for each AAA function, allowing granular control.
RADIUS supports per-command authorization for shell sessions.
Why wrong: Incorrect because per-command authorization is a feature of TACACS+, not RADIUS.
Trap 1: The aaa new-model command disables local authentication and forces…
Incorrect because aaa new-model enables AAA but does not automatically disable local authentication; method lists define the order.
Trap 2: The tacacs-server host command is used to specify the IP address…
Incorrect because tacacs-server host is for TACACS+ servers, not RADIUS.
The aaa new-model command enables AAA services on the device.
Correct because aaa new-model is required to activate AAA on Cisco IOS.
The aaa new-model command disables local authentication and forces the use of an external server.
Why wrong: Incorrect because aaa new-model enables AAA but does not automatically disable local authentication; method lists define the order.
The radius-server host command is used to specify the IP address and shared secret for a RADIUS server.
Correct because radius-server host configures the RADIUS server details.
The tacacs-server host command is used to specify the IP address and shared secret for a RADIUS server.
Why wrong: Incorrect because tacacs-server host is for TACACS+ servers, not RADIUS.
The aaa authentication login command defines a method list for login authentication.
Correct because aaa authentication login creates a method list that specifies authentication order.
Free account
Create a free account to save your results and see which topics improve across sessions.
Focused Aaa Radius Tacacs sessions
Every question in these sessions is drawn from the Aaa Radius Tacacs domain — nothing else.
Related practice questions
Move into related areas when this topic feels solid.
Sharpen your 350-401 knowledge of Architecture.
Practise 350-401 questions linked to Virtualization.
Work through 350-401 questions on Infrastructure.
Sharpen your 350-401 knowledge of Network Assurance.
Security practice questions for 350-401.
Targeted 350-401 practice covering Automation.
Practise eBGP/iBGP peering, path attributes, route selection and BGP troubleshooting.
Practise OSPF area types, LSA types, neighbour states and multi-area design.
Practise EIGRP DUAL, metrics, stub routing and route redistribution.
Practise VLAN configuration, trunk negotiation and inter-VLAN routing.
Practise RSTP, MSTP, port roles and STP protection features.
Practise extended ACLs, CoPP rate-limiting and control-plane protection.
A free account saves results across sessions and highlights which topics need work.
Sign up free