ETExamTower
Q81Security

An engineer needs to configure router R1 to validate user logins through RADIUS and use the local user database if the RADIUS server is unavailable. Which configuration must be applied?

← → navigate · a answer
Community votes
A
53% (8)
C
47% (7)
B
0% (0)
D
0% (0)
Discussion · 22
A 14
Selected Answer: A The commands are not right. They should have been: a) aaa authentication login default group radius local b) aaa authentication login default group radius c) aaa authorization exec default group radius local d) aaa authorization exec default group radius We can rule out B & D because without the "local" keyword, if the AAA server does not respond to the authentication/authorization request, the authentication/authorization fails. The reason I picked A is: "Authentication allows administrators to identify who can connect to a router by including the user's username and password." "Authorization comes into play after authentication. Authorization allows administrators to control the level of access users have after they successfully gain access to the router." Validate user logins - authentication. https://www.cisco.com/c/en/us/support/docs/security-vpn/terminal-access-controller-access-control-system-tacacs-/10384-security.html https://www.ciscopress.com/articles/article.asp?p=422947&seqNum=2
C 7
Selected Answer: C only C works. and it has a condition saying it should use local, and only that option has it. r2(config)#aaa authentication ? arap Set authentication lists for arap. attempts Set the maximum number of authentication attempts banner Message to use when starting login/authentication. dot1x Set authentication lists for IEEE 802.1x. enable Set authentication list for enable. eou Set authentication lists for EAPoUDP fail-message Message to use for failed login/authentication. login Set authentication lists for logins. onep Set authentication lists for ONEP password-prompt Text to use when prompting for a password ppp Set authentication lists for ppp. sgbp Set authentication lists for sgbp. suppress Do not send access request for a specific type of user. token token authentication username-prompt Text to use when prompting for a username r2(config)#aaa authentication
2
If the question stays the same but the answers are like this: a) aaa authentication exec default group radius local b) aaa authentication exec default group radius c) aaa authorization exec default group radius local d) aaa authorization exec default group radius, then I'd pick C.
C 2
Selected Answer: C C is right
A 2
Selected Answer: A Login is about Authentication and User's Permission is authorization.
C 2
Selected Answer: C The command aaa authentication exec is not valid in Cisco IOS.
1
it C it uses validate in the quesiton
C 1
Selected Answer: C All the commands are wrong. As the users below mentioned it should be: aaa authentication login default group radius local or aaa authorization exec default group radius local Given that all the options include "exec" I will choose C.
A 1
Selected Answer: A A is right.
1
Correct answer is C. exec default can only be used with the authorization command, for authentication to privileged EXEC command level , authentication enable default is used
1
There is no command <aaa authentication exec default []> for any purpose ....
A 1
Selected Answer: A The question says "user logins" so it means "authentication"
A 1
Selected Answer: A Definitely A. Authentication is what handles logins. Authorization is what handles what an authenticated user can do.
C 1
Selected Answer: C aaa authentication exec does not even exist. It's C because it also has the local parameter.
A 1
Selected Answer: A validating user logins is authentication, not authorisation
C 1
Selected Answer: C Its C output right from the command line (config)#aaa authorization exec default radius local
C 1
Selected Answer: C I'll go with "C" aaa authorization exec default radius local tested on CML , there is no "aaa authentication exec default radius local" command
1
Couldn't agree more! We're checking their credentials, not permissions - so we need an authentication list. A is formatted wrong; it should be: "aaa authentication login default group radius local" instead.
1
Good catch... This is about granting permission to access the shell, hense Authorization...
1
that's authorization dude, not authentication.
1
no it not. A is not correct but its a better match than C. We're talking about authentication, not authorization of commands. Am I the only one reading the questions?
A 1
Selected Answer: A aaa authentication exec default radius local - proven and tested in prod and lab... Default - radius group Fallback - local (local account from the device)