Q84Security
Refer to the exhibit. A network engineer needs to log in to the router through the console, but the RADIUS servers are unreachable. Which credentials allow console access?
← → navigate · a answer
Community votes
Discussion · 8
4
Sorry, typo. It is of course B.
B 3
Selected Answer: B
console password, no username required.
B 3
Selected Answer: B
B is the right answer.
2
I dont know man. This is a weird one. You cant have 'aaa authentication' strings in the config unless 'aaa new-model' was defined first.
You cannot remove 'aaa new-model' from a config ether. Once it is enabled, it's enabled for life unless you configured it and didnt save the config and rebooted the device.
As others here pointed out, saying aaa new-model was omitted from the output doesnt mean its gone; we have to assume it's there.
The 'aaa authentication login' strings are throwing off the whole question. If those were omitted too then there is no way to actually tell aaa new-model was turned on and we can safely assume aaa is not active on this device
However, on one hand, line con 0 is calling for group1, which will read from radius first and if not, it will take the line password.
It's a catch 22. If it does use 'line', then we interpret that aaa new-model as turned on. But then because aaa new-model is turned on, your username and password should authenticate you into the console.
In a lab, i have created this exact scenario and the answer is indeed B. but with aaa new-model turned on.
A 1
Selected Answer: A
aaa new-model is missing. So Answer A should work.
1
>aaa new-model is missing.
It's omitted. I dont think you can configure any aaa command without enabling it with ''aaa new-model"
1
Even if it were missing, the question is about accessing the console, not telnet/SSH.
The password in answer A applies to VTY
1
Correct answer is B: Console line is set to use group1, which is configured to use line credentials as a fallback, which in turn has no user name configured and only password cisco123. The test123 would only be possible if group2 was used, and group2 didn't use local fallback, which would make it use cisco/cisco, but it's used by vty only anyway, so it has to be group 1, which falls back to line cisco123