exam questions

Exam 350-401 All Questions

View all questions & answers for the 350-401 exam

Exam 350-401 topic 1 question 455 discussion

Actual exam question from Cisco's 350-401
Question #: 455
Topic #: 1
[All 350-401 Questions]


Refer to the exhibit. The network administrator must be able to perform configuration changes when all the RADIUS servers are unreachable. Which configuration allows all commands to be authorized if the user has successfully authenticated?

  • A. aaa authentication login default group radius local none
  • B. aaa authorization exec default group radius
  • C. aaa authorization exec default group radius if-authenticated
  • D. aaa authorization exec default group radius none
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
kmb192006
Highly Voted 1 year, 5 months ago
Selected Answer: C
Although C & D can both let network administrator to perform changes when RADIUS servers are unreachable, C is doing what the question asking for - "to be authorized if the user has successfully authenticated" "if-authenticated" allows user get authorized (every command the user enter is authorized) in the session if user is authenticated by any of methods defined in aaa meanwhile "none" disable authorization (every command the user enter does not need authorization) for the session if the defined authorization method in aaa is unreachable ENCOR OCG Page 775 has specified that
upvoted 9 times
...
[Removed]
Most Recent 4 months, 2 weeks ago
Selected Answer: C
C is correct
upvoted 1 times
...
dragonwise
1 year, 6 months ago
Selected Answer: D
Answer is D because RADIUS server is unavailable, and local user need to issue commands. And with "non" is there, the local user will not be subject of authorization will issue commands without restrictions
upvoted 1 times
...
Sammy3637
1 year, 7 months ago
C is correct GNS3 Output : R1(config)#aaa authorization exec default group radius ? group Use server-group. if-authenticated Succeed if user has authenticated. krb5-instance Use Kerberos instance privilege maps. local Use local database. none No authorization (always succeeds).
upvoted 2 times
...
kebkim
2 years ago
C is the answer. The aaa authorization exec default group radius if-authenticated command configures the network access server to contact the RADIUS server to determine if users are permitted to start an EXEC shell when they log in. If an error occurs when the network access server contacts the RADIUS server, the fallback method is to permit the CLI to start, provided the user has been properly authenticated.
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago