Topic 16 Practice Test 2 covers Device Access Control, Local Authentication, and AAA for Cisco 350-401 ENCOR. For broader exam preparation, review the Cisco 350-401 ENCOR Exam Dumps. Every option includes focused technical reasoning explaining both the Cisco enterprise networking concept and its fit to the scenario.
Question 1
A validation test has one explicit goal: identify why AAA method-list commands are unavailable even though TACACS+ server reachability has already been configured. Which configuration or feature should the engineer use? Choose ONE.
- SSH-only VTY transport
- aaa new-model
- AAA local fallback after server error
- RADIUS for interoperable network access
Correct Answer(s)
B
Rationale
- SSH-only VTY transport provides encrypted-only remote CLI transport, which belongs to VTY access decisions. The stem instead requires engineers to identify why AAA method-list commands are unavailable even though TACACS+ server reachability has already been configured. That result comes from aaa new-model; selecting SSH-only VTY transport would leave the tested condition unresolved.
- Aaa new-model is the functional match: it provides activation of IOS AAA processing. The question requires the network to identify why AAA method-list commands are unavailable even though TACACS+ server reachability has already been configured. That makes this the relevant AAA foundation choice for the stated evidence. This makes aaa new-model the direct fit for this case.
- AAA local fallback after server error solves a different problem by providing resilient authentication during AAA server unavailability. That matters for AAA fallback decisions, but this case requires engineers to identify why AAA method-list commands are unavailable even though TACACS+ server reachability has already been configured. aaa new-model matches the evidence more precisely.
- RADIUS for interoperable network access would affect interoperable centralized network-access AAA, a legitimate RADIUS purpose. The stem instead depends on engineers being able to identify why AAA method-list commands are unavailable even though TACACS+ server reachability has already been configured. aaa new-model provides that exact behavior, leaving this option operationally wrong.
Question 2
Operations has narrowed the incident to one decision: restore emergency console authentication after the remote AAA service is intentionally disconnected for testing. Which option should be selected next? Choose ONE.
- login authentication line binding
- login local on VTY
- AAA server reachability source interface
- local username secret
Correct Answer(s)
D
Rationale
- Login authentication line binding misses the controlling requirement because its result is attachment of the intended AAA list to the intended lines. That fits AAA application tasks. Here, the network needs engineers to restore emergency console authentication after the remote AAA service is intentionally disconnected for testing, so local username secret is the relevant mechanism.
- Login local on VTY is technically useful for per-user local authentication for the VTY lines in local authentication work. The tested task is to restore emergency console authentication after the remote AAA service is intentionally disconnected for testing, however. That behavior is governed by local username secret, making this option a distractor.
- AAA server reachability source interface is not selected because it governs predictable AAA packet sourcing and reachability. That function belongs to AAA transport work. The required task is to restore emergency console authentication after the remote AAA service is intentionally disconnected for testing, and that task is handled by local username secret.
- Use local username secret; its operational effect is a device-local user identity and protected credential. The stated task is to restore emergency console authentication after the remote AAA service is intentionally disconnected for testing. That mechanism addresses the local authentication requirement without altering an unrelated control. This makes local username secret the direct fit for this case.
Question 3
A network-services review has one requirement: replace a weak or reversible privileged-mode password mechanism with the protected IOS privileged credential. Which feature or configuration best meets it? Choose ONE.
- enable secret
- AAA exec authorization
- separate console and VTY policies
- default AAA login list
Correct Answer(s)
A
Rationale
- Enable secret is the precise choice because it yields protected privileged-EXEC access. Here, the network must replace a weak or reversible privileged-mode password mechanism with the protected IOS privileged credential. The feature therefore resolves the tested local privilege condition instead of a different issue. This makes enable secret the direct fit for this case.
- AAA exec authorization solves the wrong problem by producing post-authentication authorization for EXEC access. It fits AAA authorization needs, but the tested task is to replace a weak or reversible privileged-mode password mechanism with the protected IOS privileged credential. That requirement maps directly to enable secret.
- Separate console and VTY policies provides different authentication behavior for local and remote administration, which belongs to AAA policy design decisions. The stem instead requires engineers to replace a weak or reversible privileged-mode password mechanism with the protected IOS privileged credential. That result comes from enable secret; selecting separate console and VTY policies would leave the tested condition unresolved.
- Default AAA login list is not an equivalent substitute because it creates a common device-login authentication policy. That serves AAA authentication needs, not the requirement to replace a weak or reversible privileged-mode password mechanism with the protected IOS privileged credential. enable secret acts on the condition described in the stem.
Question 4
During verification, the team must prove or achieve the following: remediate a VTY configuration that accepts both Telnet and SSH despite a policy requiring encrypted remote administration. Which option directly matches that task? Choose ONE.
- AAA command authorization
- named AAA login list
- SSH-only VTY transport
- aaa new-model
Correct Answer(s)
C
Rationale
- Do not select AAA command authorization; its effect is per-command administrative authorization, a valid AAA authorization function. The scenario requires engineers to remediate a VTY configuration that accepts both Telnet and SSH despite a policy requiring encrypted remote administration. That requirement maps to SSH-only VTY transport, not to this alternative.
- Named AAA login list is related but operationally wrong because it yields line-specific AAA authentication policy. That supports AAA authentication work. This case requires engineers to remediate a VTY configuration that accepts both Telnet and SSH despite a policy requiring encrypted remote administration, so SSH-only VTY transport fits the stated condition.
- Use SSH-only VTY transport to obtain encrypted-only remote CLI transport. That is exactly what the team needs when it must remediate a VTY configuration that accepts both Telnet and SSH despite a policy requiring encrypted remote administration. The VTY access decision is therefore resolved by this mechanism, not the alternatives. This makes SSH-only VTY transport the direct fit for this case.
- Aaa new-model is technically useful for activation of IOS AAA processing in AAA foundation work. The tested task is to remediate a VTY configuration that accepts both Telnet and SSH despite a policy requiring encrypted remote administration, however. That behavior is governed by SSH-only VTY transport, making this option a distractor.
Question 5
A validation test has one explicit goal: fix VTY logins that still use one shared line password although unique local usernames already exist. Which configuration or feature should the engineer use? Choose ONE.
- local username secret
- AAA network authorization
- login local on VTY
- TACACS+ server group
Correct Answer(s)
C
Rationale
- Local username secret is not an equivalent substitute because it creates a device-local user identity and protected credential. That serves local authentication needs, not the requirement to fix VTY logins that still use one shared line password although unique local usernames already exist. login local on VTY acts on the condition described in the stem.
- AAA network authorization is a neighboring feature that yields authorization of network-service parameters for AAA authorization needs. This scenario requires the team to fix VTY logins that still use one shared line password although unique local usernames already exist. The required behavior belongs to login local on VTY, so this alternative is mismatched.
- Login local on VTY is correct because it creates per-user local authentication for the VTY lines. In this scenario, engineers must fix VTY logins that still use one shared line password although unique local usernames already exist. The option acts on the exact local authentication decision described in the stem. This makes login local on VTY the direct fit for this case.
- TACACS+ server group would change centralized device-administration AAA, which is appropriate in TACACS+ scenarios. The present stem asks engineers to fix VTY logins that still use one shared line password although unique local usernames already exist. That is why login local on VTY is the correct mechanism instead.
Question 6
Operations has narrowed the incident to one decision: identify which AAA list is used by a line that has no explicit named login list bound to it. Which option should be selected next? Choose ONE.
- AAA exec accounting
- default AAA login list
- enable secret
- RADIUS server group
Correct Answer(s)
B
Rationale
- AAA exec accounting does not resolve the requirement; it provides audit records for administrative session lifecycle for AAA accounting decisions. Because the stem requires engineers to identify which AAA list is used by a line that has no explicit named login list bound to it, default AAA login list is the mechanism that should be selected.
- Select default AAA login list for a common device-login authentication policy. The stem makes the requirement explicit: identify which AAA list is used by a line that has no explicit named login list bound to it. That result is governed by this AAA authentication mechanism rather than by the neighboring options. This makes default AAA login list the direct fit for this case.
- Enable secret is related but operationally wrong because it yields protected privileged-EXEC access. That supports local privilege work. This case requires engineers to identify which AAA list is used by a line that has no explicit named login list bound to it, so default AAA login list fits the stated condition.
- RADIUS server group should not be changed for this issue; it provides centralized RADIUS-backed AAA for RADIUS cases. The actual requirement is to identify which AAA list is used by a line that has no explicit named login list bound to it, which is handled by default AAA login list.
Question 7
A network-services review has one requirement: apply a special authentication order only to the console without changing the default used by every VTY line. Which feature or configuration best meets it? Choose ONE.
- named AAA login list
- SSH-only VTY transport
- AAA local fallback after server error
- AAA command accounting
Correct Answer(s)
A
Rationale
- Named AAA login list is appropriate because the result is line-specific AAA authentication policy. The scenario requires engineers to apply a special authentication order only to the console without changing the default used by every VTY line. This feature controls that AAA authentication behavior specifically, so it is the best fit. This makes named AAA login list the direct fit for this case.
- SSH-only VTY transport would change encrypted-only remote CLI transport, which is appropriate in VTY access scenarios. The present stem asks engineers to apply a special authentication order only to the console without changing the default used by every VTY line. That is why named AAA login list is the correct mechanism instead.
- AAA local fallback after server error would leave the key condition unchanged because it supplies resilient authentication during AAA server unavailability. That is useful for AAA fallback tasks, while this scenario requires the team to apply a special authentication order only to the console without changing the default used by every VTY line using named AAA login list.
- AAA command accounting fails on scenario fit: it gives audit records of administrative commands for AAA accounting decisions. The evidence says engineers must apply a special authentication order only to the console without changing the default used by every VTY line, and named AAA login list is the option that provides the needed behavior.
Question 8
During verification, the team must prove or achieve the following: select the remote AAA method when operations requires per-command control for network-device administrators. Which option directly matches that task? Choose ONE.
- login local on VTY
- login authentication line binding
- TACACS+ for granular device administration
- TACACS+ server group
Correct Answer(s)
D
Rationale
- Login local on VTY should not be changed for this issue; it provides per-user local authentication for the VTY lines for local authentication cases. The actual requirement is to select the remote AAA method when operations requires per-command control for network-device administrators, which is handled by TACACS+ server group.
- Login authentication line binding controls attachment of the intended AAA list to the intended lines and is useful for AAA application work. This case requires the team to select the remote AAA method when operations requires per-command control for network-device administrators. Because TACACS+ server group supplies that behavior, this option acts on the wrong requirement.
- TACACS+ for granular device administration targets granular centralized administration of network devices, so it fits another TACACS+ condition. The question requires the team to select the remote AAA method when operations requires per-command control for network-device administrators. Since TACACS+ server group produces the needed behavior, this choice would not fix the root requirement.
- Choose TACACS+ server group because its result is centralized device-administration AAA. The stem requires the team to select the remote AAA method when operations requires per-command control for network-device administrators. That is a direct TACACS+ match, not merely a related feature. This makes TACACS+ server group the direct fit for this case.
Question 9
A validation test has one explicit goal: select the remote AAA method for a multivendor access environment already standardized on RADIUS. Which configuration or feature should the engineer use? Choose ONE.
- AAA exec authorization
- default AAA login list
- RADIUS server group
- RADIUS for interoperable network access
Correct Answer(s)
C
Rationale
- AAA exec authorization does not match the evidence because it provides post-authentication authorization for EXEC access. That is a AAA authorization function, whereas the stem requires engineers to select the remote AAA method for a multivendor access environment already standardized on RADIUS. RADIUS server group is the option tied to that task.
- Default AAA login list would leave the key condition unchanged because it supplies a common device-login authentication policy. That is useful for AAA authentication tasks, while this scenario requires the team to select the remote AAA method for a multivendor access environment already standardized on RADIUS using RADIUS server group.
- RADIUS server group directly produces centralized RADIUS-backed AAA. That is relevant because the team needs to select the remote AAA method for a multivendor access environment already standardized on RADIUS. For this RADIUS decision, the feature changes the condition identified by the evidence. This makes RADIUS server group the direct fit for this case.
- RADIUS for interoperable network access has a different role: it supplies interoperable centralized network-access AAA in RADIUS scenarios. The engineer must select the remote AAA method for a multivendor access environment already standardized on RADIUS here. That makes RADIUS server group the direct answer and this option unsuitable.
Question 10
Operations has narrowed the incident to one decision: explain why IOS does not try the local fallback after the TACACS+ server explicitly returns an authentication reject. Which option should be selected next? Choose ONE.
- AAA local fallback after server error
- named AAA login list
- AAA command authorization
- AAA server reachability source interface
Correct Answer(s)
A
Rationale
- The required mechanism is AAA local fallback after server error, which gives resilient authentication during AAA server unavailability. The stem calls for the team to explain why IOS does not try the local fallback after the TACACS+ server explicitly returns an authentication reject. That makes this the direct AAA fallback answer rather than an adjacent workaround. This makes AAA local fallback after server error the direct fit for this case.
- Named AAA login list controls line-specific AAA authentication policy and is useful for AAA authentication work. This case requires the team to explain why IOS does not try the local fallback after the TACACS+ server explicitly returns an authentication reject. Because AAA local fallback after server error supplies that behavior, this option acts on the wrong requirement.
- AAA command authorization would be useful when per-command administrative authorization is needed for AAA authorization work. This question instead asks the team to explain why IOS does not try the local fallback after the TACACS+ server explicitly returns an authentication reject. The correct control is AAA local fallback after server error, so this alternative fails scenario fit.
- AAA server reachability source interface lacks the needed control effect; it provides predictable AAA packet sourcing and reachability for AAA transport situations. Here the team must explain why IOS does not try the local fallback after the TACACS+ server explicitly returns an authentication reject, which AAA local fallback after server error enables directly.
Question 11
A network-services review has one requirement: fix a named AAA login list that exists in global configuration but is not affecting any VTY sessions. Which feature or configuration best meets it? Choose ONE.
- TACACS+ server group
- separate console and VTY policies
- AAA network authorization
- login authentication line binding
Correct Answer(s)
D
Rationale
- TACACS+ server group does not match the evidence because it provides centralized device-administration AAA. That is a TACACS+ function, whereas the stem requires engineers to fix a named AAA login list that exists in global configuration but is not affecting any VTY sessions. login authentication line binding is the option tied to that task.
- Separate console and VTY policies is plausible because it delivers different authentication behavior for local and remote administration for AAA policy design cases. Here the team must fix a named AAA login list that exists in global configuration but is not affecting any VTY sessions. login authentication line binding directly controls that state, while this option does not.
- AAA network authorization would be an unnecessary change because it controls authorization of network-service parameters. That is relevant to AAA authorization requirements, while the current task is to fix a named AAA login list that exists in global configuration but is not affecting any VTY sessions using login authentication line binding.
- Login authentication line binding provides attachment of the intended AAA list to the intended lines. That matches the requirement to fix a named AAA login list that exists in global configuration but is not affecting any VTY sessions. It directly controls the relevant AAA application behavior, so the alternatives would change a different condition. This makes login authentication line binding the direct fit for this case.
Question 12
During verification, the team must prove or achieve the following: remediate a case where login authentication succeeds but the user must still be blocked from receiving an EXEC shell. Which option directly matches that task? Choose ONE.
- AAA exec accounting
- AAA exec authorization
- aaa new-model
- RADIUS server group
Correct Answer(s)
B
Rationale
- AAA exec accounting solves a different problem by providing audit records for administrative session lifecycle. That matters for AAA accounting decisions, but this case requires engineers to remediate a case where login authentication succeeds but the user must still be blocked from receiving an EXEC shell. AAA exec authorization matches the evidence more precisely.
- The best answer is AAA exec authorization, which supplies post-authentication authorization for EXEC access. Because the requirement is to remediate a case where login authentication succeeds but the user must still be blocked from receiving an EXEC shell, this option matches the AAA authorization decision and leaves adjacent functions untouched. This makes AAA exec authorization the direct fit for this case.
- Aaa new-model would affect activation of IOS AAA processing, a legitimate AAA foundation purpose. The stem instead depends on engineers being able to remediate a case where login authentication succeeds but the user must still be blocked from receiving an EXEC shell. AAA exec authorization provides that exact behavior, leaving this option operationally wrong.
- RADIUS server group would be useful when centralized RADIUS-backed AAA is needed for RADIUS work. This question instead asks the team to remediate a case where login authentication succeeds but the user must still be blocked from receiving an EXEC shell. The correct control is AAA exec authorization, so this alternative fails scenario fit.
Question 13
A validation test has one explicit goal: add policy enforcement for individual privileged commands after authentication and EXEC access already succeed. Which configuration or feature should the engineer use? Choose ONE.
- AAA command authorization
- local username secret
- AAA command accounting
- AAA local fallback after server error
Correct Answer(s)
A
Rationale
- AAA command authorization matches the desired state by providing per-command administrative authorization. Since engineers must add policy enforcement for individual privileged commands after authentication and EXEC access already succeed, this selection acts on the relevant AAA authorization behavior and directly satisfies the requirement. This makes AAA command authorization the direct fit for this case.
- Local username secret is not selected because it governs a device-local user identity and protected credential. That function belongs to local authentication work. The required task is to add policy enforcement for individual privileged commands after authentication and EXEC access already succeed, and that task is handled by AAA command authorization.
- AAA command accounting misses the controlling requirement because its result is audit records of administrative commands. That fits AAA accounting tasks. Here, the network needs engineers to add policy enforcement for individual privileged commands after authentication and EXEC access already succeed, so AAA command authorization is the relevant mechanism.
- AAA local fallback after server error would be an unnecessary change because it controls resilient authentication during AAA server unavailability. That is relevant to AAA fallback requirements, while the current task is to add policy enforcement for individual privileged commands after authentication and EXEC access already succeed using AAA command authorization.
Question 14
Operations has narrowed the incident to one decision: choose the authorization function for assigning network-service permissions rather than authenticating the login itself. Which option should be selected next? Choose ONE.
- login authentication line binding
- TACACS+ for granular device administration
- enable secret
- AAA network authorization
Correct Answer(s)
D
Rationale
- Login authentication line binding solves a different problem by providing attachment of the intended AAA list to the intended lines. That matters for AAA application decisions, but this case requires engineers to choose the authorization function for assigning network-service permissions rather than authenticating the login itself. AAA network authorization matches the evidence more precisely.
- TACACS+ for granular device administration solves the wrong problem by producing granular centralized administration of network devices. It fits TACACS+ needs, but the tested task is to choose the authorization function for assigning network-service permissions rather than authenticating the login itself. That requirement maps directly to AAA network authorization.
- Enable secret provides protected privileged-EXEC access, which belongs to local privilege decisions. The stem instead requires engineers to choose the authorization function for assigning network-service permissions rather than authenticating the login itself. That result comes from AAA network authorization; selecting enable secret would leave the tested condition unresolved.
- Choose AAA network authorization. It creates authorization of network-service parameters, while the stem requires engineers to choose the authorization function for assigning network-service permissions rather than authenticating the login itself. This directly satisfies the AAA authorization condition and avoids changing a feature that is not implicated. This makes AAA network authorization the direct fit for this case.
Question 15
A network-services review has one requirement: close an audit gap where successful logins are visible but the start and stop time of EXEC sessions is missing. Which feature or configuration best meets it? Choose ONE.
- RADIUS for interoperable network access
- SSH-only VTY transport
- AAA exec accounting
- AAA exec authorization
Correct Answer(s)
C
Rationale
- Do not select RADIUS for interoperable network access; its effect is interoperable centralized network-access AAA, a valid RADIUS function. The scenario requires engineers to close an audit gap where successful logins are visible but the start and stop time of EXEC sessions is missing. That requirement maps to AAA exec accounting, not to this alternative.
- SSH-only VTY transport is technically useful for encrypted-only remote CLI transport in VTY access work. The tested task is to close an audit gap where successful logins are visible but the start and stop time of EXEC sessions is missing, however. That behavior is governed by AAA exec accounting, making this option a distractor.
- AAA exec accounting fits because it delivers audit records for administrative session lifecycle. The scenario specifically asks engineers to close an audit gap where successful logins are visible but the start and stop time of EXEC sessions is missing. This is the AAA accounting control that changes the tested behavior directly. This makes AAA exec accounting the direct fit for this case.
- AAA exec authorization misses the controlling requirement because its result is post-authentication authorization for EXEC access. That fits AAA authorization tasks. Here, the network needs engineers to close an audit gap where successful logins are visible but the start and stop time of EXEC sessions is missing, so AAA exec accounting is the relevant mechanism.
Question 16
During verification, the team must prove or achieve the following: close an audit gap where session records exist but reviewers cannot determine which privileged commands were executed. Which option directly matches that task? Choose ONE.
- AAA server reachability source interface
- AAA command accounting
- AAA command authorization
- login local on VTY
Correct Answer(s)
B
Rationale
- AAA server reachability source interface is a neighboring feature that yields predictable AAA packet sourcing and reachability for AAA transport needs. This scenario requires the team to close an audit gap where session records exist but reviewers cannot determine which privileged commands were executed. The required behavior belongs to AAA command accounting, so this alternative is mismatched.
- For this case, AAA command accounting supplies audit records of administrative commands. The operational need is to close an audit gap where session records exist but reviewers cannot determine which privileged commands were executed. That correspondence makes it the correct AAA accounting mechanism for the scenario. This makes AAA command accounting the direct fit for this case.
- AAA command authorization solves the wrong problem by producing per-command administrative authorization. It fits AAA authorization needs, but the tested task is to close an audit gap where session records exist but reviewers cannot determine which privileged commands were executed. That requirement maps directly to AAA command accounting.
- Login local on VTY is not an equivalent substitute because it creates per-user local authentication for the VTY lines. That serves local authentication needs, not the requirement to close an audit gap where session records exist but reviewers cannot determine which privileged commands were executed. AAA command accounting acts on the condition described in the stem.
Question 17
A validation test has one explicit goal: explain why TACACS+ is favored over a basic access-authentication design when command-by-command device administration is required. Which configuration or feature should the engineer use? Choose ONE.
- default AAA login list
- separate console and VTY policies
- AAA network authorization
- TACACS+ for granular device administration
Correct Answer(s)
D
Rationale
- Default AAA login list is related but operationally wrong because it yields a common device-login authentication policy. That supports AAA authentication work. This case requires engineers to explain why TACACS+ is favored over a basic access-authentication design when command-by-command device administration is required, so TACACS+ for granular device administration fits the stated condition.
- Separate console and VTY policies does not resolve the requirement; it provides different authentication behavior for local and remote administration for AAA policy design decisions. Because the stem requires engineers to explain why TACACS+ is favored over a basic access-authentication design when command-by-command device administration is required, TACACS+ for granular device administration is the mechanism that should be selected.
- Do not select AAA network authorization; its effect is authorization of network-service parameters, a valid AAA authorization function. The scenario requires engineers to explain why TACACS+ is favored over a basic access-authentication design when command-by-command device administration is required. That requirement maps to TACACS+ for granular device administration, not to this alternative.
- TACACS+ for granular device administration is the functional match: it provides granular centralized administration of network devices. The question requires the network to explain why TACACS+ is favored over a basic access-authentication design when command-by-command device administration is required. That makes this the relevant TACACS+ choice for the stated evidence. This makes TACACS+ for granular device administration the direct fit for this case.
Question 18
Operations has narrowed the incident to one decision: explain why RADIUS remains suitable when many vendors must participate in one centralized network-access authentication service. Which option should be selected next? Choose ONE.
- RADIUS for interoperable network access
- AAA exec accounting
- aaa new-model
- named AAA login list
Correct Answer(s)
A
Rationale
- Use RADIUS for interoperable network access; its operational effect is interoperable centralized network-access AAA. The stated task is to explain why RADIUS remains suitable when many vendors must participate in one centralized network-access authentication service. That mechanism addresses the RADIUS requirement without altering an unrelated control. This makes RADIUS for interoperable network access the direct fit for this case.
- AAA exec accounting is a neighboring feature that yields audit records for administrative session lifecycle for AAA accounting needs. This scenario requires the team to explain why RADIUS remains suitable when many vendors must participate in one centralized network-access authentication service. The required behavior belongs to RADIUS for interoperable network access, so this alternative is mismatched.
- Aaa new-model fails on scenario fit: it gives activation of IOS AAA processing for AAA foundation decisions. The evidence says engineers must explain why RADIUS remains suitable when many vendors must participate in one centralized network-access authentication service, and RADIUS for interoperable network access is the option that provides the needed behavior.
- Named AAA login list would change line-specific AAA authentication policy, which is appropriate in AAA authentication scenarios. The present stem asks engineers to explain why RADIUS remains suitable when many vendors must participate in one centralized network-access authentication service. That is why RADIUS for interoperable network access is the correct mechanism instead.
Question 19
A network-services review has one requirement: fix AAA requests denied by a firewall because the device sources them from different routed interfaces after path changes. Which feature or configuration best meets it? Choose ONE.
- AAA command accounting
- local username secret
- AAA server reachability source interface
- TACACS+ server group
Correct Answer(s)
C
Rationale
- AAA command accounting does not resolve the requirement; it provides audit records of administrative commands for AAA accounting decisions. Because the stem requires engineers to fix AAA requests denied by a firewall because the device sources them from different routed interfaces after path changes, AAA server reachability source interface is the mechanism that should be selected.
- Local username secret targets a device-local user identity and protected credential, so it fits another local authentication condition. The question requires the team to fix AAA requests denied by a firewall because the device sources them from different routed interfaces after path changes. Since AAA server reachability source interface produces the needed behavior, this choice would not fix the root requirement.
- AAA server reachability source interface is the precise choice because it yields predictable AAA packet sourcing and reachability. Here, the network must fix AAA requests denied by a firewall because the device sources them from different routed interfaces after path changes. The feature therefore resolves the tested AAA transport condition instead of a different issue. This makes AAA server reachability source interface the direct fit for this case.
- TACACS+ server group should not be changed for this issue; it provides centralized device-administration AAA for TACACS+ cases. The actual requirement is to fix AAA requests denied by a firewall because the device sources them from different routed interfaces after path changes, which is handled by AAA server reachability source interface.
Question 20
During verification, the team must prove or achieve the following: keep local console recovery available when a TACACS+ outage interrupts WAN-based VTY authentication. Which option directly matches that task? Choose ONE.
- enable secret
- separate console and VTY policies
- RADIUS server group
- TACACS+ for granular device administration
Correct Answer(s)
B
Rationale
- Enable secret has a different role: it supplies protected privileged-EXEC access in local privilege scenarios. The engineer must keep local console recovery available when a TACACS+ outage interrupts WAN-based VTY authentication here. That makes separate console and VTY policies the direct answer and this option unsuitable.
- Use separate console and VTY policies to obtain different authentication behavior for local and remote administration. That is exactly what the team needs when it must keep local console recovery available when a TACACS+ outage interrupts WAN-based VTY authentication. The AAA policy design decision is therefore resolved by this mechanism, not the alternatives. This makes separate console and VTY policies the direct fit for this case.
- RADIUS server group would leave the key condition unchanged because it supplies centralized RADIUS-backed AAA. That is useful for RADIUS tasks, while this scenario requires the team to keep local console recovery available when a TACACS+ outage interrupts WAN-based VTY authentication using separate console and VTY policies.
- TACACS+ for granular device administration fails on scenario fit: it gives granular centralized administration of network devices for TACACS+ decisions. The evidence says engineers must keep local console recovery available when a TACACS+ outage interrupts WAN-based VTY authentication, and separate console and VTY policies is the option that provides the needed behavior.