300-440 exam dumps

300-440 practice question 205 of 293

Designing and Implementing Cloud Connectivity. Professional level, Cisco. Free question with the correct answer and a full explanation.

300-440 Question 205

Single answer

A network administrator is troubleshooting an authentication issue on a Cisco router configured with AAA using a TACACS+ server. Users report that they are unable to log in to the router. Upon verifying the configuration, the administrator notices the following partial configuration:

aaa new-model
aaa authentication login default group tacacs+ local
tacacs-server host 192.168.10.1 key secretkey

What is the most likely issue causing the authentication failure?

  1. A

    The TACACS+ server IP address is incorrect.

  2. B

    The local database fallback is not configured properly.

  3. C

    The shared secret key is mismatched between the router and the TACACS+ server.

  4. D

    The 'aaa new-model' command is missing in the configuration.

Show answer and explanation

Correct answer: C

Explanation

In this scenario, the most likely cause of the authentication failure is a shared secret key mismatch between the router and the TACACS+ server. The shared secret key is used to encrypt communication between the router and the TACACS+ server, and if the keys do not match, authentication attempts will fail. The configuration snippet provided shows that the 'aaa new-model' command is enabled, the TACACS+ server IP address is configured, and the local fallback is properly set up, leaving the key mismatch as the most probable issue.

  • A. Incorrect.

    The TACACS+ server IP address appears correct as per the configuration. If it were incorrect, the router would not be able to reach the server, but the issue here points to authentication failure, not reachability.

  • B. Incorrect.

    The configuration specifies a local database fallback with 'local', meaning if the TACACS+ server is unavailable, the router will use the local database. This fallback is properly configured.

  • C. Correct.

    A shared secret key mismatch is a common cause of authentication failures with TACACS+. If the key configured on the router does not match the key on the TACACS+ server, authentication will fail.

  • D. Incorrect.

    The 'aaa new-model' command is present in the configuration, so it is not the issue in this scenario.

Timed practice exam

Take a 300-440 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam