Q28Infrastructure Security
Refer to the exhibit. An engineer is attempting to configure local authentication on the console line, but the device is attempting TACACS+ authentication. Which action results in the desired configuration?
← → navigate · a answer
Community votes
Discussion · 5
12
D seems right:
Example 2: Console Access Using Line Password
Let's extend the configuration from Example 1 so that console login is authenticated only by the password set on line con 0.
The list CONSOLE is defined and then applied to line con 0.
We configure:
Router(config)# aaa authentication login CONSOLE line
In the command above:
the named list is CONSOLE.
there is just one authentication method (line).
After a named list (in this example, CONSOLE) is created, it has to be applied to a line or interface for it to take effect. This is done with the login authentication list_name command:
Router(config)# line con 0
Router(config-line)# exec-timeout 0 0
Router(config-line)# password cisco
Router(config-line)# login authentication CONSOLE
https://www.cisco.com/c/en/us/support/docs/security-vpn/terminal-access-controller-access-control-system-tacacs-/10384-security.html
D 6
Selected Answer: D
D is correct, the default authentication group is being used and you want it to use the Console group
4
D is correct. There are 2 authentication profiles here: (1) default and (2) Console. (1) will authenticate first with TACACS+ (that is stated in the question) and (2) has not been applied to the console. D is tying (2) to con 0 configuration.
1
The answer given is correct D
1
Correct
Also aaa authorization isn't enabled by default for the console so a user doesn't accidentally lock himself out (ENCOR OCG), but the aaa default authentication list is automatically used on the console.