Cisco CCNA 200-301 AAA Practice Test

Topic 38 focuses on AAA for the Cisco Certified Network Associate (CCNA) certification and the 200-301 exam, using Cisco networking and Cisco IOS concepts where relevant. For broader exam preparation, review the Cisco CCNA 200-301 Exam Dumps page. Each question includes a concise explanation of the correct answer and the technical reason the other choices are incorrect.

Question 1

Which AAA function verifies who a user or device is?

  1. Authentication
  2. Local AAA
  3. Authorization
  4. AAA server group

Correct Answer: A

 

Correct Answer

Answer A is correct because the selected answer describes the AAA function that verifies who a user or device is.

Incorrect Answers

Answer B is incorrect because the “Local AAA” option describes a different concept: AAA processing that uses credentials or methods configured directly on the network device.

Answer C is incorrect because the “Authorization” option describes a different concept: the AAA function that determines what an authenticated user or device is permitted to do.

Answer D is incorrect because the “AAA server group” option describes a different concept: a logical collection of external authentication servers that a device can use as a method source.

 

Question 2

Which AAA function determines what an authenticated user or device is permitted to do?

  1. Method list
  2. AAA server group
  3. Authorization
  4. Authentication

Correct Answer: C

 

Correct Answer

Answer C is correct because the selected answer describes the AAA function that determines what an authenticated user or device is permitted to do.

Incorrect Answers

Answer A is incorrect because the “Method list” option describes a different concept: an ordered AAA configuration that specifies which authentication or authorization methods should be attempted.

Answer B is incorrect because the “AAA server group” option describes a different concept: a logical collection of external authentication servers that a device can use as a method source.

Answer D is incorrect because the “Authentication” option describes a different concept: the AAA function that verifies who a user or device is.

 

Question 3

Which AAA function records activity such as logins, commands, or resource usage?

  1. Local AAA
  2. Authentication
  3. Accounting
  4. AAA server group

Correct Answer: C

 

Correct Answer

Answer C is correct because the selected answer describes the AAA function that records activity such as logins, commands, or resource usage.

Incorrect Answers

Answer A is incorrect because the “Local AAA” option describes a different concept: AAA processing that uses credentials or methods configured directly on the network device.

Answer B is incorrect because the “Authentication” option describes a different concept: the AAA function that verifies who a user or device is.

Answer D is incorrect because the “AAA server group” option describes a different concept: a logical collection of external authentication servers that a device can use as a method source.

 

Question 4

Which centralized AAA protocol widely is used for network access and supported for administrative authentication?

  1. Accounting
  2. RADIUS
  3. AAA server group
  4. TACACS+

Correct Answer: B

 

Correct Answer

Answer B is correct because the selected answer describes a centralized AAA protocol widely used for network access and supported for administrative authentication.

Incorrect Answers

Answer A is incorrect because the “Accounting” option describes a different concept: the AAA function that records activity such as logins, commands, or resource usage.

Answer C is incorrect because the “AAA server group” option describes a different concept: a logical collection of external authentication servers that a device can use as a method source.

Answer D is incorrect because the “TACACS+” option describes a different concept: a centralized AAA protocol often used for device administration and granular command authorization.

 

Question 5

Which centralized AAA protocol often is used for device administration and granular command authorization?

  1. AAA server group
  2. TACACS+
  3. Authorization
  4. Authentication

Correct Answer: B

 

Correct Answer

Answer B is correct because the selected answer describes a centralized AAA protocol often used for device administration and granular command authorization.

Incorrect Answers

Answer A is incorrect because the “AAA server group” option describes a different concept: a logical collection of external authentication servers that a device can use as a method source.

Answer C is incorrect because the “Authorization” option describes a different concept: the AAA function that determines what an authenticated user or device is permitted to do.

Answer D is incorrect because the “Authentication” option describes a different concept: the AAA function that verifies who a user or device is.

 

Question 6

Which term describes AAA processing that uses credentials or methods configured directly on the network device?

  1. Local AAA
  2. Authentication
  3. Authorization
  4. RADIUS

Correct Answer: A

 

Correct Answer

Answer A is correct because AAA processing that uses credentials or methods configured directly on the network device.

Incorrect Answers

Answer B is incorrect because the “Authentication” option describes a different concept: the AAA function that verifies who a user or device is.

Answer C is incorrect because the “Authorization” option describes a different concept: the AAA function that determines what an authenticated user or device is permitted to do.

Answer D is incorrect because the “RADIUS” option describes a different concept: a centralized AAA protocol widely used for network access and supported for administrative authentication.

 

Question 7

Which logical collection of external authentication servers a device can use as a method source?

  1. AAA server group
  2. Authentication
  3. TACACS+
  4. Authorization

Correct Answer: A

 

Correct Answer

Answer A is correct because the selected answer describes a logical collection of external authentication servers that a device can use as a method source.

Incorrect Answers

Answer B is incorrect because the “Authentication” option describes a different concept: the AAA function that verifies who a user or device is.

Answer C is incorrect because the “TACACS+” option describes a different concept: a centralized AAA protocol often used for device administration and granular command authorization.

Answer D is incorrect because the “Authorization” option describes a different concept: the AAA function that determines what an authenticated user or device is permitted to do.

 

Question 8

Which ordered AAA configuration specifies which authentication or authorization methods should be attempted?

  1. Authentication
  2. Method list
  3. TACACS+
  4. Authorization

Correct Answer: B

 

Correct Answer

Answer B is correct because the selected answer describes an ordered AAA configuration that specifies which authentication or authorization methods should be attempted.

Incorrect Answers

Answer A is incorrect because the “Authentication” option describes a different concept: the AAA function that verifies who a user or device is.

Answer C is incorrect because the “TACACS+” option describes a different concept: a centralized AAA protocol often used for device administration and granular command authorization.

Answer D is incorrect because the “Authorization” option describes a different concept: the AAA function that determines what an authenticated user or device is permitted to do.

 

Question 9

Which secondary AAA method is used if a preferred external service is unavailable?

  1. Method list
  2. AAA server group
  3. Fallback method
  4. RADIUS

Correct Answer: C

 

Correct Answer

Answer C is correct because the selected answer describes a secondary AAA method used if a preferred external service is unavailable.

Incorrect Answers

Answer A is incorrect because the “Method list” option describes a different concept: an ordered AAA configuration that specifies which authentication or authorization methods should be attempted.

Answer B is incorrect because the “AAA server group” option describes a different concept: a logical collection of external authentication servers that a device can use as a method source.

Answer D is incorrect because the “RADIUS” option describes a different concept: a centralized AAA protocol widely used for network access and supported for administrative authentication.

 

Question 10

What is an architecture in which authentication and policy decisions are provided by shared external servers rather than configured independently on every device?

  1. Centralized AAA
  2. TACACS+
  3. Fallback method
  4. Authentication

Correct Answer: A

 

Correct Answer

Answer A is correct because the selected answer describes an architecture in which authentication and policy decisions are provided by shared external servers rather than configured independently on every device.

Incorrect Answers

Answer B is incorrect because the “TACACS+” option describes a different concept: a centralized AAA protocol often used for device administration and granular command authorization.

Answer C is incorrect because the “Fallback method” option describes a different concept: a secondary AAA method used if a preferred external service is unavailable.

Answer D is incorrect because the “Authentication” option describes a different concept: the AAA function that verifies who a user or device is.

 

Question 11

For Authentication, which statement is accurate?

  1. A logical collection of external authentication servers that a device can use as a method source.
  2. The AAA function that verifies who a user or device is.
  3. An ordered AAA configuration that specifies which authentication or authorization methods should be attempted.
  4. AAA processing that uses credentials or methods configured directly on the network device.

Correct Answer: B

 

Correct Answer

Answer B is correct because the choice accurately describes Authentication: The AAA function that verifies who a user or device is.

Incorrect Answers

Answer A is incorrect because the “AAA server group” option describes a different concept: a logical collection of external authentication servers that a device can use as a method source.

Answer C is incorrect because the “Method list” option describes a different concept: an ordered AAA configuration that specifies which authentication or authorization methods should be attempted.

Answer D is incorrect because the “Local AAA” option describes a different concept: AAA processing that uses credentials or methods configured directly on the network device.

 

Question 12

For Authorization, which statement is accurate?

  1. A centralized AAA protocol widely used for network access and supported for administrative authentication.
  2. The AAA function that determines what an authenticated user or device is permitted to do.
  3. The AAA function that verifies who a user or device is.
  4. AAA processing that uses credentials or methods configured directly on the network device.

Correct Answer: B

 

Correct Answer

Answer B is correct because the selected answer describes the AAA function that determines what an authenticated user or device is permitted to do.

Incorrect Answers

Answer A is incorrect because the “RADIUS” option describes a different concept: a centralized AAA protocol widely used for network access and supported for administrative authentication.

Answer C is incorrect because the “Authentication” option describes a different concept: the AAA function that verifies who a user or device is.

Answer D is incorrect because the “Local AAA” option describes a different concept: AAA processing that uses credentials or methods configured directly on the network device.

 

Question 13

For Accounting, which statement is accurate?

  1. A secondary AAA method used if a preferred external service is unavailable.
  2. A logical collection of external authentication servers that a device can use as a method source.
  3. The AAA function that verifies who a user or device is.
  4. The AAA function that records activity such as logins, commands, or resource usage.

Correct Answer: D

 

Correct Answer

Answer D is correct because the selected answer describes the AAA function that records activity such as logins, commands, or resource usage.

Incorrect Answers

Answer A is incorrect because the “Fallback method” option describes a different concept: a secondary AAA method used if a preferred external service is unavailable.

Answer B is incorrect because the “AAA server group” option describes a different concept: a logical collection of external authentication servers that a device can use as a method source.

Answer C is incorrect because the “Authentication” option describes a different concept: the AAA function that verifies who a user or device is.

 

Question 14

A network-access design sends user authentication requests to a centralized AAA service. Which statement describes the role that RADIUS can provide?

  1. A secondary AAA method used if a preferred external service is unavailable.
  2. A centralized AAA protocol often used for device administration and granular command authorization.
  3. A logical collection of external authentication servers that a device can use as a method source.
  4. A centralized AAA protocol widely used for network access and supported for administrative authentication.

Correct Answer: D

 

Correct Answer

Answer D is correct because it accurately defines RADIUS. The matching definition is: A centralized AAA protocol widely used for network access and supported for administrative authentication.

Incorrect Answers

Answer A is incorrect because the “Fallback method” option describes a different concept: a secondary AAA method used if a preferred external service is unavailable.

Answer B is incorrect because the “TACACS+” option describes a different concept: a centralized AAA protocol often used for device administration and granular command authorization.

Answer C is incorrect because the “AAA server group” option describes a different concept: a logical collection of external authentication servers that a device can use as a method source.

 

Question 15

A network operations team needs centralized device-administration AAA with command-level authorization. Which statement accurately describes the role of TACACS+ in this design?

  1. A centralized AAA protocol often used for device administration and granular command authorization.
  2. AAA processing that uses credentials or methods configured directly on the network device.
  3. A centralized AAA protocol widely used for network access and supported for administrative authentication.
  4. A secondary AAA method used if a preferred external service is unavailable.

Correct Answer: A

 

Correct Answer

Answer A is correct because the choice accurately describes TACACS+: A centralized AAA protocol often used for device administration and granular command authorization.

Incorrect Answers

Answer B is incorrect because the “Local AAA” option describes a different concept: AAA processing that uses credentials or methods configured directly on the network device.

Answer C is incorrect because the “RADIUS” option describes a different concept: a centralized AAA protocol widely used for network access and supported for administrative authentication.

Answer D is incorrect because the “Fallback method” option describes a different concept: a secondary AAA method used if a preferred external service is unavailable.

 

Question 16

For Local AAA, which statement is accurate?

  1. An ordered AAA configuration that specifies which authentication or authorization methods should be attempted.
  2. The AAA function that determines what an authenticated user or device is permitted to do.
  3. The AAA function that verifies who a user or device is.
  4. AAA processing that uses credentials or methods configured directly on the network device.

Correct Answer: D

 

Correct Answer

Answer D is correct because AAA processing that uses credentials or methods configured directly on the network device.

Incorrect Answers

Answer A is incorrect because the “Method list” option describes a different concept: an ordered AAA configuration that specifies which authentication or authorization methods should be attempted.

Answer B is incorrect because the “Authorization” option describes a different concept: the AAA function that determines what an authenticated user or device is permitted to do.

Answer C is incorrect because the “Authentication” option describes a different concept: the AAA function that verifies who a user or device is.

 

Question 17

For AAA server group, which statement is accurate?

  1. An ordered AAA configuration that specifies which authentication or authorization methods should be attempted.
  2. A centralized AAA protocol widely used for network access and supported for administrative authentication.
  3. The AAA function that verifies who a user or device is.
  4. A logical collection of external authentication servers that a device can use as a method source.

Correct Answer: D

 

Correct Answer

Answer D is correct because the selected answer describes a logical collection of external authentication servers that a device can use as a method source.

Incorrect Answers

Answer A is incorrect because the “Method list” option describes a different concept: an ordered AAA configuration that specifies which authentication or authorization methods should be attempted.

Answer B is incorrect because the “RADIUS” option describes a different concept: a centralized AAA protocol widely used for network access and supported for administrative authentication.

Answer C is incorrect because the “Authentication” option describes a different concept: the AAA function that verifies who a user or device is.

 

Question 18

For Method list, which statement is accurate?

  1. A logical collection of external authentication servers that a device can use as a method source.
  2. An architecture in which authentication and policy decisions are provided by shared external servers rather than configured independently on every device.
  3. The AAA function that determines what an authenticated user or device is permitted to do.
  4. An ordered AAA configuration that specifies which authentication or authorization methods should be attempted.

Correct Answer: D

 

Correct Answer

Answer D is correct because it accurately defines Method list. The matching definition is: An ordered AAA configuration that specifies which authentication or authorization methods should be attempted.

Incorrect Answers

Answer A is incorrect because the “AAA server group” option describes a different concept: a logical collection of external authentication servers that a device can use as a method source.

Answer B is incorrect because the “Centralized AAA” option describes a different concept: an architecture in which authentication and policy decisions are provided by shared external servers rather than configured independently on every device.

Answer C is incorrect because the “Authorization” option describes a different concept: the AAA function that determines what an authenticated user or device is permitted to do.

 

Question 19

For Fallback method, which statement is accurate?

  1. A centralized AAA protocol widely used for network access and supported for administrative authentication.
  2. A centralized AAA protocol often used for device administration and granular command authorization.
  3. A secondary AAA method used if a preferred external service is unavailable.
  4. The AAA function that determines what an authenticated user or device is permitted to do.

Correct Answer: C

 

Correct Answer

Answer C is correct because the choice accurately describes Fallback method: A secondary AAA method used if a preferred external service is unavailable.

Incorrect Answers

Answer A is incorrect because the “RADIUS” option describes a different concept: a centralized AAA protocol widely used for network access and supported for administrative authentication.

Answer B is incorrect because the “TACACS+” option describes a different concept: a centralized AAA protocol often used for device administration and granular command authorization.

Answer D is incorrect because the “Authorization” option describes a different concept: the AAA function that determines what an authenticated user or device is permitted to do.

 

Question 20

For Centralized AAA, which statement is accurate?

  1. The AAA function that verifies who a user or device is.
  2. AAA processing that uses credentials or methods configured directly on the network device.
  3. A centralized AAA protocol widely used for network access and supported for administrative authentication.
  4. An architecture in which authentication and policy decisions are provided by shared external servers rather than configured independently on every device.

Correct Answer: D

 

Correct Answer

Answer D is correct because the selected answer describes an architecture in which authentication and policy decisions are provided by shared external servers rather than configured independently on every device.

Incorrect Answers

Answer A is incorrect because the “Authentication” option describes a different concept: the AAA function that verifies who a user or device is.

Answer B is incorrect because the “Local AAA” option describes a different concept: AAA processing that uses credentials or methods configured directly on the network device.

Answer C is incorrect because the “RADIUS” option describes a different concept: a centralized AAA protocol widely used for network access and supported for administrative authentication.

 

Question 21

A device checks presented credentials before establishing a user’s identity. Which AAA function is being performed at this stage?

  1. RADIUS
  2. Authentication
  3. Local AAA
  4. Accounting

Correct Answer: B

 

Correct Answer

Answer B is correct because the scenario is describing the role of Authentication. The AAA function that verifies who a user or device is.

Incorrect Answers

Answer A is incorrect because the “RADIUS” option describes a different concept: a centralized AAA protocol widely used for network access and supported for administrative authentication.

Answer C is incorrect because the “Local AAA” option describes a different concept: AAA processing that uses credentials or methods configured directly on the network device.

Answer D is incorrect because the “Accounting” option describes a different concept: the AAA function that records activity such as logins, commands, or resource usage.

 

Question 22

During a defensive configuration review, the design calls for the following capability: The AAA function that determines what an authenticated user or device is permitted to do. Which option names that capability most accurately?

  1. Centralized AAA
  2. TACACS+
  3. Authorization
  4. Local AAA

Correct Answer: C

 

Correct Answer

Answer C is correct because Authorization directly provides the function required by the scenario. The AAA function that determines what an authenticated user or device is permitted to do.

Incorrect Answers

Answer A is incorrect because the “Centralized AAA” option describes a different concept: an architecture in which authentication and policy decisions are provided by shared external servers rather than configured independently on every device.

Answer B is incorrect because the “TACACS+” option describes a different concept: a centralized AAA protocol often used for device administration and granular command authorization.

Answer D is incorrect because the “Local AAA” option describes a different concept: AAA processing that uses credentials or methods configured directly on the network device.

 

Question 23

An administrator needs a record of login sessions and commands used after access is granted. Which AAA function produces these records?

  1. Fallback method
  2. RADIUS
  3. Method list
  4. Accounting

Correct Answer: D

 

Correct Answer

Answer D is correct because the operational requirement in the stem maps to Accounting: The AAA function that records activity such as logins, commands, or resource usage.

Incorrect Answers

Answer A is incorrect because the “Fallback method” option describes a different concept: a secondary AAA method used if a preferred external service is unavailable.

Answer B is incorrect because the “RADIUS” option describes a different concept: a centralized AAA protocol widely used for network access and supported for administrative authentication.

Answer C is incorrect because the “Method list” option describes a different concept: an ordered AAA configuration that specifies which authentication or authorization methods should be attempted.

 

Question 24

While working on an access-control investigation, an administrator encounters this requirement: A centralized AAA protocol widely used for network access and supported for administrative authentication. Which answer is the most precise match?

  1. Authorization
  2. Authentication
  3. RADIUS
  4. Fallback method

Correct Answer: C

 

Correct Answer

Answer C is correct because RADIUS is the most precise fit for the stated requirement. A centralized AAA protocol widely used for network access and supported for administrative authentication.

Incorrect Answers

Answer A is incorrect because the “Authorization” option describes a different concept: the AAA function that determines what an authenticated user or device is permitted to do.

Answer B is incorrect because the “Authentication” option describes a different concept: the AAA function that verifies who a user or device is.

Answer D is incorrect because the “Fallback method” option describes a different concept: a secondary AAA method used if a preferred external service is unavailable.

 

Question 25

In a campus security deployment, the team must identify the technology that provides the following function: A centralized AAA protocol often used for device administration and granular command authorization. Which option should be selected?

  1. TACACS+
  2. RADIUS
  3. Authentication
  4. AAA server group

Correct Answer: A

 

Correct Answer

Answer A is correct because the scenario is describing the role of TACACS+. A centralized AAA protocol often used for device administration and granular command authorization.

Incorrect Answers

Answer B is incorrect because the “RADIUS” option describes a different concept: a centralized AAA protocol widely used for network access and supported for administrative authentication.

Answer C is incorrect because the “Authentication” option describes a different concept: the AAA function that verifies who a user or device is.

Answer D is incorrect because the “AAA server group” option describes a different concept: a logical collection of external authentication servers that a device can use as a method source.

 

Question 26

A network device performs its AAA checks using methods and credentials configured on the device itself. Which AAA deployment model is this?

  1. AAA server group
  2. Local AAA
  3. RADIUS
  4. Method list

Correct Answer: B

 

Correct Answer

Answer B is correct because Local AAA directly provides the function required by the scenario. AAA processing that uses credentials or methods configured directly on the network device.

Incorrect Answers

Answer A is incorrect because the “AAA server group” option describes a different concept: a logical collection of external authentication servers that a device can use as a method source.

Answer C is incorrect because the “RADIUS” option describes a different concept: a centralized AAA protocol widely used for network access and supported for administrative authentication.

Answer D is incorrect because the “Method list” option describes a different concept: an ordered AAA configuration that specifies which authentication or authorization methods should be attempted.

 

Question 27

During a defensive configuration review, the design calls for the following capability: A logical collection of external authentication servers that a device can use as a method source. Which option names that capability most accurately?

  1. AAA server group
  2. Method list
  3. Centralized AAA
  4. RADIUS

Correct Answer: A

 

Correct Answer

Answer A is correct because the operational requirement in the stem maps to AAA server group: A logical collection of external authentication servers that a device can use as a method source.

Incorrect Answers

Answer B is incorrect because the “Method list” option describes a different concept: an ordered AAA configuration that specifies which authentication or authorization methods should be attempted.

Answer C is incorrect because the “Centralized AAA” option describes a different concept: an architecture in which authentication and policy decisions are provided by shared external servers rather than configured independently on every device.

Answer D is incorrect because the “RADIUS” option describes a different concept: a centralized AAA protocol widely used for network access and supported for administrative authentication.

 

Question 28

An administrator defines the ordered methods a device should try when authenticating a connection. Which AAA configuration object records this order?

  1. RADIUS
  2. Method list
  3. Authorization
  4. Centralized AAA

Correct Answer: B

 

Correct Answer

Answer B is correct because Method list is the most precise fit for the stated requirement. An ordered AAA configuration that specifies which authentication or authorization methods should be attempted.

Incorrect Answers

Answer A is incorrect because the “RADIUS” option describes a different concept: a centralized AAA protocol widely used for network access and supported for administrative authentication.

Answer C is incorrect because the “Authorization” option describes a different concept: the AAA function that determines what an authenticated user or device is permitted to do.

Answer D is incorrect because the “Centralized AAA” option describes a different concept: an architecture in which authentication and policy decisions are provided by shared external servers rather than configured independently on every device.

 

Question 29

While working on an access-control investigation, an administrator encounters this requirement: A secondary AAA method used if a preferred external service is unavailable. Which answer is the most precise match?

  1. Fallback method
  2. AAA server group
  3. Authentication
  4. Method list

Correct Answer: A

 

Correct Answer

Answer A is correct because the scenario is describing the role of Fallback method. A secondary AAA method used if a preferred external service is unavailable.

Incorrect Answers

Answer B is incorrect because the “AAA server group” option describes a different concept: a logical collection of external authentication servers that a device can use as a method source.

Answer C is incorrect because the “Authentication” option describes a different concept: the AAA function that verifies who a user or device is.

Answer D is incorrect because the “Method list” option describes a different concept: an ordered AAA configuration that specifies which authentication or authorization methods should be attempted.

 

Question 30

In a campus security deployment, the team must identify the technology that provides the following function: An architecture in which authentication and policy decisions are provided by shared external servers rather than configured independently on every device. Which option should be selected?

  1. Local AAA
  2. Fallback method
  3. Centralized AAA
  4. Authorization

Correct Answer: C

 

Correct Answer

Answer C is correct because Centralized AAA directly provides the function required by the scenario. An architecture in which authentication and policy decisions are provided by shared external servers rather than configured independently on every device.

Incorrect Answers

Answer A is incorrect because the “Local AAA” option describes a different concept: AAA processing that uses credentials or methods configured directly on the network device.

Answer B is incorrect because the “Fallback method” option describes a different concept: a secondary AAA method used if a preferred external service is unavailable.

Answer D is incorrect because the “Authorization” option describes a different concept: the AAA function that determines what an authenticated user or device is permitted to do.

img