exam questions

Exam 350-601 All Questions

View all questions & answers for the 350-601 exam

Exam 350-601 topic 1 question 262 discussion

Actual exam question from Cisco's 350-601
Question #: 262
Topic #: 1
[All 350-601 Questions]


Refer to the exhibit. A network engineer requires remote access via SSH to a Cisco MDS 9000 Series Switch. The solution must support secure access using the local user database when the RADIUS servers are unreachable from the switches. Which command meets these requirements?

  • A. aaa authentication none
  • B. aaa authentication login default group radius
  • C. aaa authentication login default fallback error local
  • D. aaa authentication login default group local
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
subject10
Highly Voted 3 years, 8 months ago
It's "B". Fallback is on by default Disabling Fallback to Local Authentication By default, if remote authentication is configured for console or default login and all AAA servers are unreachable (resulting in an authentication error), the Cisco NX-OS device falls back to local authentication to ensure that users are not locked out of the device. However, you can disable fallback to local authentication in order to increase security. https://www.cisco.com/c/en/us/td/docs/switches/datacenter/nexus9000/sw/6-x/security/configuration/guide/b_Cisco_Nexus_9000_Series_NX-OS_Security_Configuration_Guide/b_Cisco_Nexus_9000_Series_NX-OS_Security_Configuration_Guide_chapter_0111.html
upvoted 11 times
Valkyrie17
3 years, 7 months ago
I agree, by default NX-OS will fall back to local authentication. Thanks for the explanation.
upvoted 2 times
...
...
corelate_9
Highly Voted 3 years ago
it doesn't state that fallback is enabled or disabled, therefore, to ensure that fallback is already not disable, we can use "aaa authentication login default fallback error local"
upvoted 5 times
C4rlos
2 years, 3 months ago
Yes, but this command will not enable radius authentication, hence B is correct.
upvoted 1 times
...
...
pboniface
Most Recent 1 week ago
Selected Answer: C
Answer is C
upvoted 1 times
...
Rollizo
6 months, 3 weeks ago
Selected Answer: B
“The fallback error local method enables fallback to local authentication for the default login if remote authentication is configured and all AAA servers are unreachable. Fallback to local authentication is enabled by default.” It is B because it is the only one with radius and local authentication is included by default
upvoted 2 times
...
elper
10 months, 2 weeks ago
Selected Answer: B
Assuming the MDS behaves the same as Nexus, it should be B (fallback is enabled by default, and the "local" keyword is not required).
upvoted 1 times
...
asd248402
11 months, 4 weeks ago
Selected Answer: C
https://www.cisco.com/c/en/us/td/docs/switches/datacenter/sw/5_x/nx-os/security/configuration/guide/b_Cisco_Nexus_7000_NX-OS_Security_Configuration_Guide__Release_5-x/b_Cisco_Nexus_7000_NX-OS_Security_Configuration_Guide__Release_5-x_chapter_0100.html
upvoted 2 times
...
RFV147
1 year, 8 months ago
Selected Answer: C
Answer is C. The lnk to Nexus 9000 is incorrect. The question is about MDS: Configuring Fallback Mechanism for Authentication https://www.cisco.com/c/en/us/td/docs/dcn/mds9000/sw/9x/configuration/security/cisco-mds-9000-nx-os-security-configuration-guide-9x.pdf
upvoted 3 times
GoForCCNP
10 months ago
This documentation says: "The fallback is set to local by default in case of an authentication error", so answer must be B!
upvoted 1 times
...
...
Gayan84
1 year, 11 months ago
The default login method is local , which is used when no methods are configured or when all the configured methods fail to respond, unless fallback to local is disabled for the console login. The local keyword is not supported (and is not required) when configuring AAA authentication groups because local authentication is the default if remote servers are unreachable. For example, if you configure aaa authentication login default group g1 , local authentication is tried if you are unable to authenticate using AAA group g1. In contrast, if you configure aaa authentication login default group g1 none , no authentication is performed if you are unable to authenticate using AAA group g1.
upvoted 1 times
Gayan84
1 year, 11 months ago
Hence I will select ans << B >>
upvoted 1 times
...
...
paradigm88
2 years ago
Selected Answer: B
The local option is the default method when other configured options fail. You can disable the local option for the console or default login by using the no aaa authentication login { console | default } fallback error local command.
upvoted 2 times
...
GuyThatTakesDumps
2 years, 6 months ago
Selected Answer: B
is B https://www.cisco.com/c/en/us/support/docs/security-vpn/terminal-access-controller-access-control-system-tacacs-/10384-security.html#:~:text=All%20users%20are%20authenticated%20with%20the%20Radius%20server%20(the%20first%20method).%20If%20the%20Radius%20server%20does%20not%20respond%2C%20then%20the%20router%20local%20database%20is%20used%20(the%20second%20method).%20For%20local%20authentication%2C%20define%20the%20username%20name%20and%20password%3A
upvoted 1 times
...
cypher9
2 years, 10 months ago
C. aaa authentication login default fallback error local
upvoted 2 times
...
MajklNajt
3 years, 8 months ago
I bet this is B as the referenced link states (under Configuring Default Login Authentication Methods): The default console login method is local, which is used when no methods are configured or when all the configured methods fail to respond, unless fallback to local is disabled for the console login. AND ...The local keyword is not supported (and is not required) when configuring AAA authentication groups because local authentication is the default if remote servers are unreachable. For example, if you configure aaa authentication login default group g1, local authentication is tried if you are unable to authenticate using AAA group g1.
upvoted 3 times
onix
3 years, 8 months ago
Agree, answer: B https://www.cisco.com/c/en/us/td/docs/switches/datacenter/mds9000/sw/8_x/config/security/cisco_mds9000_security_config_guide_8x/configuring_security_features_on_external_aaa_server.html "When you have configured server groups using the server group authentication method, an authentication request is sent to the first AAA server in the group. (...) If all configured methods fail, then by default local database is used for authentication. (...) The fallback is set to local by default in case of an authentication error."
upvoted 4 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago