CiscoCisco
350-401 · Question #129
350-401 Question #129: Real Exam Question with Answer & Explanation
The correct answer is D: Local authentication is maintained on the router.. Local AAA authentication uses credentials stored on the device itself, while Kerberos authentication can enforce account lockout policies as part of its security framework.
Submitted by krish.m· Mar 6, 2026[DOMAIN LIST MISSING IN PROMPT]
Question
Which two statements about AAA authentication are true? (Choose two)
Options
- ARADIUS authentication queries the router's local username database.
- BTACASCS+ authentication uses an RSA server to authenticate users.
- CLocal user names are case-insensitive.
- DLocal authentication is maintained on the router.
- EKRB5 authentication disables user access when an incorrect password is entered.
Explanation
Local AAA authentication uses credentials stored on the device itself, while Kerberos authentication can enforce account lockout policies as part of its security framework.
Common mistakes.
- A. RADIUS authentication queries an external RADIUS server for user credentials, not the router's local username database.
- B. TACACS+ authentication relies on a dedicated TACACS+ server to validate user credentials, not specifically an RSA server, although an RSA SecurID system could be used as a backend authentication source for a TACACS+ server.
- C. On Cisco IOS devices, local usernames are typically case-sensitive, meaning that 'Admin' and 'admin' are treated as distinct accounts.
Concept tested. AAA authentication methods and features
Topics
#AAA authentication#RADIUS#TACACS+#Local authentication
Community Discussion
No community discussion yet for this question.