Courseiva

350-401 · topic practice

Aaa Radius Tacacs practice questions

Practise ENCOR 350-401 Aaa Radius Tacacs practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Aaa Radius Tacacs

What the exam tests

What to know about Aaa Radius Tacacs

Aaa Radius Tacacs questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Aaa Radius Tacacs exam traps

  • ▸Answering from memory before reading the full scenario.
  • ▸Missing a constraint such as cost, availability, security, scope or command context.
  • ▸Choosing a broad answer when the question asks for the most specific fix.
  • ▸Ignoring why the wrong options are tempting.

Practice set

Aaa Radius Tacacs questions

20 questions · select your answer, then reveal the explanation

Question 1hardmultiple choice
Read the full wireless explanation →

A company is deploying a new Cisco wireless LAN controller (WLC) and wants to use RADIUS for authenticating wireless users. The WLC is configured with the RADIUS server IP, shared secret, and authentication port 1812. However, users are unable to authenticate. The network engineer checks the RADIUS server logs and sees that the server is receiving authentication requests from the WLC but is responding with an 'Access-Reject' message. The WLC logs show 'RADIUS server not responding' for the same server. What is the most likely cause?

Question 2mediummultiple choice
Open the full VLAN trunking answer →

A network engineer is configuring a Cisco switch for 802.1X port-based authentication. The switch is configured with a RADIUS server for authentication. The engineer wants to allow devices that fail 802.1X authentication to still access a limited guest VLAN. The engineer configures 'authentication port-control auto' and 'authentication host-mode multi-host' on the interface. However, when a non-802.1X-capable device is connected, the port remains in the unauthorized state and does not fall into the guest VLAN. What is missing?

Question 3easymultiple choice
Study the full AAA explanation →

What is the default quiet-period timer value in Cisco IOS 802.1X configuration?

Question 4mediumdrag order
Study the full AAA explanation →

Drag and drop the steps of 802.1X port authentication with MAB fallback into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5
Question 5hardmultiple choice
Study the full AAA explanation →

An enterprise is implementing Cisco TrustSec (CTS) to enforce role-based access control. The network engineer configures the switch with 'cts role-based enforcement' and 'cts manual' on an interface connecting to a trusted Cisco switch. The engineer also configures Security Group Tags (SGTs) on the RADIUS server. However, traffic between two hosts in different SGTs is not being filtered as expected. The engineer checks 'show cts role-based counters' and sees no drops. What is the most likely reason for the lack of enforcement?

Question 6mediummultiple choice
Study the full ACL explanation →

A network engineer is configuring 802.1X on a Cisco switch for a guest network. The engineer wants to allow guests to access the internet after authentication but restrict access to internal resources. The engineer configures the switch with 'authentication port-control auto' and a downloadable ACL (dACL) from the RADIUS server. After a guest authenticates, the engineer tests connectivity and finds that the guest can access internal servers. What is the most likely cause?

Question 7mediummultiple choice
Study the full SD-Access breakdown →

An architect is designing an SD-Access fabric for a campus network that requires segmentation of guest, employee, and IoT traffic. The design must use Cisco TrustSec for policy enforcement. Which component is responsible for assigning the Security Group Tag (SGT) to endpoints upon authentication?

Question 8mediummultiple choice
Study the full AAA explanation →

A network administrator issues the following command on a Cisco switch:

Switch# show aaa servers

RADIUS: id 1, priority 1, host 192.168.1.10, auth-port 1812, acct-port 1813 State: current UP, duration 3600s, previous duration 0s Dead: total 0, retransmit 0 RADIUS: id 2, priority 2, host 192.168.1.20, auth-port 1812, acct-port 1813 State: current UP, duration 100s, previous duration 300s Dead: total 3, retransmit 2

Based on this output, what can be concluded?

Question 9mediummultiple choice
Open the full VLAN trunking answer →

An organization is implementing 802.1X for wireless users using Cisco ISE as the RADIUS server. The network engineer configures the wireless LAN controller (WLC) with 802.1X authentication. Users report that they can connect to the SSID but cannot access any network resources. The engineer checks the WLC and sees that users are authenticated and assigned to VLAN 100. The engineer also checks the switchport connecting the WLC and sees it is a trunk. What is the most likely issue?

Question 10mediummultiple choice
Study the full AAA explanation →

Consider this AAA configuration:

aaa new-model
aaa authentication login default local
aaa authorization exec default local
aaa accounting exec default start-stop group tacacs+

tacacs-server host 10.0.0.1 key SecretKey

line con 0

login authentication default

line vty 0 4

login authentication default

What is the effect of this configuration?

Question 11mediummultiple choice
Study the full AAA explanation →

In Cisco TrustSec, which component is responsible for assigning a Security Group Tag (SGT) to a user or device based on authentication?

Question 12mediummatching
Study the full AAA explanation →

Drag and drop each TACACS+ packet type on the left to its matching function on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Initiates an authentication session and contains the username

Sends a challenge (e.g., password prompt) or authentication result

Carries the user's response to a challenge

Indicates successful authentication and may include authorization attributes

Indicates authentication failure

Question 13mediumdrag order
Study the full AAA explanation →

Drag and drop the steps of the 802.1X EAP-TLS authentication exchange into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5
Question 14mediumdrag order
Study the full AAA explanation →

Drag and drop the steps of AAA method list fallback from RADIUS to local into the correct order, from first to last.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4
5Step 5
Question 15hardmultiple choice
Read the full EtherChannel explanation →

A network engineer runs the following command on Switch SW7:

SW7# show interfaces port-channel 1

Port-channel1 is up, line protocol is up (connected) Hardware is EtherChannel, address is aaaa.bbbb.cccc (bia aaaa.bbbb.cccc) Description: Link to Core Internet address is 192.168.1.1/30 MTU 1500 bytes, BW 2000000 Kbit/sec, DLY 10 usec, reliability 255/255, txload 1/255, rxload 1/255

Encapsulation ARPA, loopback not set

Keepalive set (10 sec) Full-duplex, 1000Mb/s, link type is auto, media type is unknown input flow-control is off, output flow-control is unsupported ARP type: ARPA, ARP Timeout 04:00:00 Last input 00:00:00, output 00:00:00, output hang never Last clearing of "show interface" counters never Input queue: 0/2000/0/0 (size/max/drops/flushes); Total output drops: 0 Queueing strategy: fifo Output queue: 0/40 (size/max) 5 minute input rate 1000 bits/sec, 2 packets/sec 5 minute output rate 500 bits/sec, 1 packets/sec 12345 packets input, 1234567 bytes, 0 no buffer Received 0 broadcasts (0 IP multicasts) 0 runts, 0 giants, 0 throttles 0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored 0 watchdog, 0 multicast, 0 pause input 0 input packets with dribble condition detected 67890 packets output, 9876543 bytes, 0 underruns 0 output errors, 0 collisions, 2 interface resets 0 unknown protocol drops 0 babbles, 0 late collision, 0 deferred 0 lost carrier, 0 no carrier, 0 pause output 0 output buffer failures, 0 output buffers swapped out

Based on this output, what can be concluded?

Question 16mediummultiple choice
Study the full AAA explanation →

Consider this AAA configuration:

aaa new-model
aaa authentication login default group tacacs+ local
aaa authorization exec default group tacacs+ local
aaa accounting exec default stop-only group tacacs+

tacacs-server host 10.0.0.1 key SecretKey tacacs-server host 10.0.0.2 key SecretKey

What is the effect of the accounting command?

Question 17mediummatching
Study the full AAA explanation →

Drag and drop each 802.1X component on the left to its matching role on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Client device requesting network access

Network device that enforces port-based access control

RADIUS server that validates credentials and returns authorization attributes

Protocol used between supplicant and authenticator to carry EAP frames

Protocol used between authenticator and authentication server for AAA

Question 18hardmultiple choice
Read the full wireless explanation →

An enterprise network uses TACACS+ for device administration and RADIUS for network access (VPN and wireless). The TACACS+ server is configured to authorize commands. A network engineer notices that after a recent upgrade of the TACACS+ server software, some commands that were previously authorized are now being denied. The engineer checks the router configuration and sees 'aaa authorization commands 15 default group tacacs+'. The TACACS+ server logs show that the authorization requests are being sent and responded to. What is the most likely cause?

Question 19hardmultiple choice
Study the full AAA explanation →

A network administrator runs the following debug on a router:

R1# debug aaa authorization

*Mar  1 00:02:45.678: AAA/AUTHOR/EXEC(00000002): Processing author request for user 'jdoe'
*Mar  1 00:02:45.678: AAA/AUTHOR/EXEC(00000002): Method=TACACS+
*Mar  1 00:02:45.678: AAA/AUTHOR/EXEC(00000002): TACACS+ server 10.1.1.10:49, timeout 5
*Mar  1 00:02:45.678: AAA/AUTHOR/EXEC(00000002): Sent author request
*Mar  1 00:02:45.678: AAA/AUTHOR/EXEC(00000002): Received PASS response
*Mar  1 00:02:45.678: AAA/AUTHOR/EXEC(00000002): Pass

Based on this output, what can be concluded?

Question 20mediummatching
Study the full AAA explanation →

Drag and drop each RADIUS attribute name on the left to its matching attribute number on the right.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

1

4

6

8

22

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Aaa Radius Tacacs sessions

Start a Aaa Radius Tacacs only practice session

Every question in these sessions is drawn from the Aaa Radius Tacacs domain — nothing else.

Related practice questions

Related 350-401 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the 350-401 exam test about Aaa Radius Tacacs?
Aaa Radius Tacacs questions test whether you can apply the concept in context, not just recognise a definition.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Aaa Radius Tacacs questions in a focused session?
Yes — the session launcher on this page draws every question from the Aaa Radius Tacacs domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other 350-401 topics?
Use the topic links above to move to related areas, or go back to the 350-401 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the 350-401 exam covers. They are not copied from any real exam or dump site.