nerdexam
Cisco

350-701 · Question #679

Refer to the exhibit. Logins from internal users to a Cisco Adaptive Security Appliance firewall must be performed by using a TACACS server. The firewall is already configured. Which additional…

The correct answer is A. ASA(config)# aaa-server SERVERGROUP (external) host 4.4.4.2 ASA(config-aaa-server-host)# key Cisco4512! Option A is correct because on a Cisco ASA, the interface name used in the aaa-server command must match the actual logical interface name configured on the device (e.g., 'external'), and the TACACS+ server IP address 4.4.4.2 resides on that external-facing interface. The key…

Submitted by priya_blr· Mar 30, 2026Network Security – Configuring AAA authentication on Cisco ASA using TACACS+ for administrative access control

Question

Refer to the exhibit. Logins from internal users to a Cisco Adaptive Security Appliance firewall must be performed by using a TACACS server. The firewall is already configured. Which additional configuration must be performed to configure the TACACS+ server group with a key of Cisco4512!? A. B. C. D.

Exhibit

350-701 question #679 exhibit

Options

  • AASA(config)# aaa-server SERVERGROUP (external) host 4.4.4.2 ASA(config-aaa-server-host)# key Cisco4512!
  • BASA(config)# aaa-server SERVERGROUP (inside) host 192.168.10.1 ASA(config-aaa-server-host)# key Cisco4512!
  • CASA(config)# aaa-server SERVERGROUP (internal) host 192.168.10.10 ASA(config-aaa-server-host)# key Cisco4512!
  • DASA(config)# aaa-server SERVERGROUP (outside) host 4.4.4.2 ASA(config-aaa-server-host)# key Cisco4512!

How the community answered

(47 responses)
  • A
    74% (35)
  • B
    13% (6)
  • C
    4% (2)
  • D
    9% (4)

Explanation

Option A is correct because on a Cisco ASA, the interface name used in the aaa-server command must match the actual logical interface name configured on the device (e.g., 'external'), and the TACACS+ server IP address 4.4.4.2 resides on that external-facing interface. The key 'Cisco4512!' is correctly applied under the aaa-server-host configuration submode. The interface name in parentheses must reflect where the AAA server is reachable, and the host IP must match the actual TACACS+ server address shown in the exhibit.

Topics

#Cisco ASA#AAA Configuration#TACACS+#Firewall Authentication

Community Discussion

No community discussion yet for this question.

Full 350-701 Practice