nerdexam
Cisco

350-001 · Question #24

Refer to the exhibit. What would be the security risk when you are using the above configuration?

The correct answer is D. If the TACACS+ server failed, no authentication would be required. You could use the aaa authentication login default tacacs+ enable command to specify that if your TACACS+ server fails to respond, you can log in to the access server by using your enable password. If you do not have an enable password set on the router, you will not be able to…

Security

Question

Refer to the exhibit. What would be the security risk when you are using the above configuration?

Options

  • AThe locally configured users would override the TACACS+ security policy.
  • BIt would be impossible to log in to the router if the TACACS+ server is down.
  • CThe default login policy would override the TACACS+ configuration.
  • DIf the TACACS+ server failed, no authentication would be required.

How the community answered

(48 responses)
  • A
    2% (1)
  • B
    10% (5)
  • C
    4% (2)
  • D
    83% (40)

Explanation

You could use the aaa authentication login default tacacs+ enable command to specify that if your TACACS+ server fails to respond, you can log in to the access server by using your enable password. If you do not have an enable password set on the router, you will not be able to log in to it until you have a functioning TACACS+ UNIX daemon or Windows NT or Windows 2000 server process configured with usernames and passwords. The enable password in this case is a last-resort authentication method. You also can specify none as the last-resort method, which means that no authentication is required if all other methods failed.

Topics

#TACACS+#AAA authentication#authentication fallback#security risk

Community Discussion

No community discussion yet for this question.

Full 350-001 Practice