exam questions

Exam 350-601 All Questions

View all questions & answers for the 350-601 exam

Exam 350-601 topic 1 question 256 discussion

Actual exam question from Cisco's 350-601
Question #: 256
Topic #: 1
[All 350-601 Questions]

Refer to the exhibit.

What is the result of implementing this configuration?

  • A. The switch queries the TACACS+ server by using an encrypted text PAP login.
  • B. The TACACS+ server uses the type-6 encrypted format.
  • C. The switch queries the TACACS+ server by using a clear text PAP login.
  • D. The timeout value on the TACACS+ server is 10 seconds.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
AllenT
Highly Voted 3 years, 3 months ago
I think this is A. Deadtime is set in minutes and "key 7" means an encrypted login
upvoted 13 times
...
ciscochick
Highly Voted 3 years, 1 month ago
Answer is A tacacs-server key To configure a global TACACS+ shared secret key, use the tacacs-server key command. To remove a configured shared secret, use the no form of this command. tacacs-server key [0 | 7] shared-secret Syntax Description 7 (Optional) Configures a preshared key specified in encrypted text to authenticate communication between the TACACS+ client and server.
upvoted 8 times
...
Scheldon
Most Recent 6 months ago
Selected Answer: A
A https://community.cisco.com/t5/routing/does-cisco-support-strong-remote-network-authentication/m-p/2767297/highlight/false#M257295:~:text=To%20sum%20up%2C%20Tacacs%20encrypt%20the%20PAP%20protocol%20so%20there%20is%20no%20login/pwd%20in%20clear%20text%20in%20the%20request.
upvoted 2 times
...
Selected Answer: A
A is correct!
upvoted 2 times
...
niunius
1 year, 2 months ago
A is correct. The PAP message is in plain text between switch and end user.. but from swicth to AAA server its encrypted. https://community.cisco.com/t5/network-access-control/tacacs-pap-ascii/td-p/1989127
upvoted 1 times
...
harmann
1 year, 2 months ago
Selected Answer: C
C because PAP by definition does not send password encrypted. https://www.techopedia.com/definition/4043/password-authentication-protocol-pap#:~:text=Password%20Authentication%20Protocol%20(PAP)%20is,authentication%20server%20as%20plain%20text.
upvoted 1 times
C4rlos
10 months, 3 weeks ago
Yes, but One of the unique features offered by TACACS+ is encryption of the entire packet beyond the header. This feature distinguishes it from RADIUS, which can encrypt only the passwords exchanged rather than the entire packet.
upvoted 1 times
...
...
Smoothey
1 year, 7 months ago
Selected Answer: A
The timeout is set to 5 seconds in the config. PAP is sent encrypted. Deadtime is only the amount of time to query a non responding AAA server amd in minutes.
upvoted 1 times
...
Alfi91
2 years ago
Blurain is right. PAP authenticates in clear text. "key 7" means you provide the key in an encrypted format to the device, so if someone looks at the config file, they would not see the actual key. So I think the answer is C, because the key is only encrypted in the config file, but the question is about how PAP authenticates, and it does it in clear text.
upvoted 2 times
Alfi91
2 years ago
But I really don't know what the answer means by "encrypted text". Encrypted in the config or encrypted during the authentication?
upvoted 1 times
RTL_dude
1 year, 8 months ago
I think it means that it sends the type-7 (or type-6 if AES128 encryption is enabled) "encrypted" password through PAP without encrypting the packet itself otherwise.
upvoted 1 times
SwitchKiller
1 year, 6 months ago
I think the implication here is that PAP is doing the encryption when, as has been discussed, PAP sends in Clear Text, so that would make the Answer C. We've already established D is wrong as the Deadtime is in Minutes not seconds and B is wrong because at no point in the configuration does it mention Type 6 encryption
upvoted 1 times
...
...
...
...
blurain
2 years, 6 months ago
PAP is clear text, not encrypted
upvoted 3 times
...
tazerman
2 years, 7 months ago
the answer is C. using invetred commas assumes you have alerady run an encryption of the password and so uses clear text. if you dont use the inverted commas then the password will be double encrypted ( thats my understanding anyway )
upvoted 1 times
DC4000
2 years, 6 months ago
A is correct You can specify that the key-value is in clear text format (0 )... type-7 encrypted (7 ). The Cisco NX-OS software encrypts a clear text key before saving it to the running configuration. The default format is clear text. The maximum length is 63 characters... If you already configured a shared secret using the generate type7_encrypted_secret command, enter it in quotation marks, as shown in the second example. For more information, see Configuring the Shared Secret for RADIUS or TACACS+. https://help.webex.com/en-us/n6idlrb/Configuring-TACACS
upvoted 1 times
...
...
Heyyeh71
3 years, 3 months ago
Answer is A. switch(config)# tacacs-server key [ 0 | 7 ] key-value Specifies a preshared key for all TACACS+ servers. You can specify a clear text (0) or encrypted (7) preshared key. https://www.cisco.com/c/en/us/td/docs/switches/datacenter/nexus5000/sw/configuration/guide/cli/CLIConfigurationGuide/sec_tacacsplus.html
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago