Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam 300-410 All Questions

View all questions & answers for the 300-410 exam

Exam 300-410 topic 1 question 261 discussion

Actual exam question from Cisco's 300-410
Question #: 261
Topic #: 1
[All 300-410 Questions]


Refer to the exhibit. An administrator configured a Cisco router for TACACS authentication, but the router is using the local enable password instead. Which action resolves the issue?

  • A. Configure the aaa authentication login default group admin local if-authenticated command instead.
  • B. Configure the aaa authentication login admin group tacacs+ local enable none command instead.
  • C. Configure the aaa authentication login admin group tacacs+ local if-authenticated command instead.
  • D. Configure the aaa authentication login admin group admin local enable command instead.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
potato_inet0
Highly Voted 1 year, 5 months ago
Well, first of all the question seems to be wrong. We can see the admin method defined and the group is tacacs+ , tacacs server is defined as well as a tacacs server-group. By applying the aaa authentication login admin group tacacs+ local enable the device should use the defined tacacs server and succesfully communicate, so based on the config there is no issue, I've tested it in LAB. From the answers D is most logical, the others do not make sense, however the point is the question is wrong.
upvoted 5 times
bk989
1 month, 2 weeks ago
There may be multiple tacacs+ groups. This is the best I can think of. However yes the config in the exhibit is correct it will be using the tacacs server admin. But D explicitly defines using this server group named "admin", not all the tacacs+ groups. This is best I can think of.
upvoted 1 times
...
...
HungarianDish_111
Highly Voted 1 year, 5 months ago
Selected Answer: D
"A" is not reflecting the solution from here: https://community.cisco.com/t5/network-access-control/problem-setting-7606-router-for-tacacs-authentication/td-p/2316903 "A" adds " if-authenticated", which is used with authorization method lists, and not for authentication. "D" defines method list "admin" and uses it for "line vty" configuration, which is correct. Some examples: https://www.netprojnetworks.com/cisco-9800-tacacs-config-cli-and-verify-notes/
upvoted 5 times
...
SeMo0o0o0
Most Recent 2 months, 3 weeks ago
Selected Answer: D
D is correct
upvoted 1 times
...
Rob_CCNP000
1 year, 2 months ago
Selected Answer: D
Correct answer is D the configuration in the exhibit is using a TACACS+ server group called tacacs+ that does not exist. The group is called admin!
upvoted 3 times
...
inteldarvid
1 year, 3 months ago
Selected Answer: D
D is correct: https://community.cisco.com/t5/network-access-control/if-authenticated/td-p/1248124
upvoted 2 times
...
VergilP
1 year, 11 months ago
Selected Answer: D
please review cisco website in jarz 's comment but I vote for D the tacacs+ group name is "admin", so it must be "group admin" not "group tacacs+" so B , C is out and if-authenticated command is use for aaa authorization so I choose D
upvoted 2 times
...
Huntkey
2 years ago
Selected Answer: D
I think it is D. The vty line is using the method "admin" and the method "admin" uses the TACACS+ group admin. In the original config, it used a wrong TACACS+ group name that is undefined. Then it doesn't have a local username or password I think. Therefore, causing authentication to refer to the enable password.
upvoted 2 times
Huntkey
2 years ago
a little correction. It was using the TACACS+ group "local" and it is undefined. The "local" here is not for using the local credentials
upvoted 1 times
...
...
jarz
2 years ago
Selected Answer: A
aaa authentication login default group admin local enable https://community.cisco.com/t5/network-access-control/problem-setting-7606-router-for-tacacs-authentication/td-p/2316903
upvoted 1 times
VergilP
1 year, 11 months ago
aaa authentication login default group admin local enable So You mean answer is D?
upvoted 1 times
...
VergilP
1 year, 11 months ago
OH , I see the comment below.. in the cisco community --- Please replace the below listed command aaa authentication login admin group tacacs+ local enable with; aaa authentication login default group admin local enable
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...