350-701 · Question #679
Refer to the exhibit. Logins from internal users to a Cisco Adaptive Security Appliance firewall must be performed by using a TACACS server. The firewall is already configured. Which additional…
The correct answer is A. ASA(config)# aaa-server SERVERGROUP (external) host 4.4.4.2 ASA(config-aaa-server-host)# key Cisco4512! Option A is correct because on a Cisco ASA, the interface name used in the aaa-server command must match the actual logical interface name configured on the device (e.g., 'external'), and the TACACS+ server IP address 4.4.4.2 resides on that external-facing interface. The key…
Question
Refer to the exhibit. Logins from internal users to a Cisco Adaptive Security Appliance firewall must be performed by using a TACACS server. The firewall is already configured. Which additional configuration must be performed to configure the TACACS+ server group with a key of Cisco4512!? A. B. C. D.
Exhibit
Options
- AASA(config)# aaa-server SERVERGROUP (external) host 4.4.4.2 ASA(config-aaa-server-host)# key Cisco4512!
- BASA(config)# aaa-server SERVERGROUP (inside) host 192.168.10.1 ASA(config-aaa-server-host)# key Cisco4512!
- CASA(config)# aaa-server SERVERGROUP (internal) host 192.168.10.10 ASA(config-aaa-server-host)# key Cisco4512!
- DASA(config)# aaa-server SERVERGROUP (outside) host 4.4.4.2 ASA(config-aaa-server-host)# key Cisco4512!
How the community answered
(47 responses)- A74% (35)
- B13% (6)
- C4% (2)
- D9% (4)
Explanation
Option A is correct because on a Cisco ASA, the interface name used in the aaa-server command must match the actual logical interface name configured on the device (e.g., 'external'), and the TACACS+ server IP address 4.4.4.2 resides on that external-facing interface. The key 'Cisco4512!' is correctly applied under the aaa-server-host configuration submode. The interface name in parentheses must reflect where the AAA server is reachable, and the host IP must match the actual TACACS+ server address shown in the exhibit.
Topics
Community Discussion
No community discussion yet for this question.
