ETExamTower
Q44Secure Network Access, Visibility, and Enforcement

Which Cisco command globally enables authentication, authorization, and accounting so that CoA is supported on the device?

← → navigate · a answer
Community votes
C
71% (10)
A
29% (4)
B
0% (0)
D
0% (0)
Discussion · 18
25
aaa new-model Enables authentication, authorization, and accounting (AAA) globally. aaa server radius dynamic-author Sets up the local AAA server for the dynamic authorization service, which has to be enabled to support the CoA functionality to push the policy map in an input and output direction, and enters dynamic authorization local server configuration mode. https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_usr_aaa/configuration/15-sy/sec-usr-aaa-15-sy-book/sec-rad-coa.html
A 5
Selected Answer: A Guys, you have to use reverse logic here. > if you issue an "aaa new-model" you dont have CoA support as is disabled by default on all devices. > if you issue "aaa server radius dynamic-author" this will turn on CoA globally (assuming that aaa new-model is already there)
C 3
Selected Answer: C So both commands, "aaa new-model" and "aaa server radius dynamic-author," can be used to enable CoA on a Cisco device, but they do different jobs. The "aaa new-model" command is used to enable AAA globally on the device, while the "aaa server radius dynamic-author" command is used to configure a RADIUS server for dynamic authorization.
C 3
Selected Answer: C It's C. you cannot enable anything before first issuing "aaa new-model". So all AAA commands are not available befor you add "aaa new-model" therefor the answer is C
C 2
Selected Answer: C aaa server radius dynamic-author does not enable aaa globally. Therefore C
A 2
Selected Answer: A A is the correct answer don't be fooled: Proof: https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/security/a1/sec-a1-xe-3se-3850-cr-book/sec-a1-xe-3se-3850-cr-book_chapter_01.html#wp4234596077 aaa new-model: To enable the authentication, authorization, and accounting (AAA) access control model, issue the aaa new-model command in global configuration mode. To disable the AAA access control model, use the no form of this command. aaa server radius dynamic-author: ( to facilitate interaction with an external policy server) To configure a device as an authentication, authorization, and accounting (AAA) server to facilitate interaction with an external policy server, use the aaa server radius dynamic-authorcommand in global configuration mode. To remove this configuration, use the no form of this command.
A 2
Selected Answer: A Just what Ampersand and Jessie45785 said
A 2
Selected Answer: A aaa new-model Enables authentication, authorization, and accounting (AAA) globally I think the aaa server radius dynamic-author command needs to be enabled globally to support the CoA
C 2
Selected Answer: C Step 3 aaa new-model Example: Device(config)# aaa new-model Enables authentication, authorization, and accounting (AAA) globally. https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_usr_aaa/configuration/15-sy/sec-usr-aaa-15-sy-book/sec-rad-coa.html
C 2
Selected Answer: C simple.. dynamic author turns on COA , aaa new model allows COA to be enabled.. C is the correct.
C 2
Selected Answer: C To enable AAA, you have to configure the 'aaa new-model' command in global configuration mode. Until this command is enabled, ALL OTHER AAA commands are hidden. https://www.cisco.com/c/en/us/support/docs/security-vpn/terminal-access-controller-access-control-system-tacacs-/10384-security.html
C 2
Selected Answer: C The question says "Which Cisco command enables authentication, authorization, and accounting globally" - the rest does not matter here. With that being the case, the only correct answer is C. Once AAA is enabled globally, THEN you would use the command "aaa server radius dynamic-author" to enable CoA
C 1
Selected Answer: C definitely C
1
It's C. Cisco says that Step 3: aaa new-model "Enables authentication, authorization, and accounting (AAA) globally." This command comes before Step 4: aaa server radius dynamic-author, which "Enters dynamic authorization local server configuration mode and specifies a RADIUS client from which a device accepts Change of Authorization (CoA) and disconnect requests. Configures the device as a AAA server to facilitate interaction with an external policy server." So the command aaa new-model is needed BEFORE aaa server radius dynamic-author, for it to function. Answer is C. Source: Cisco RADIUS Change of Authorization paper - https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_usr_aaa/configuration/xe-16-10/sec-usr-aaa-xe-16-10-book/sec-rad-coa.pdf
1
... and says "so that CoA >>IS<< supported..." so the command turned on CoA. If the Q wording was different i.e. "... so that to be able to support CoA..." , then the right answer would be C "aaa new-model" (but not with the above wording, which makes A the correct answer).
1
Answer C
1
A is right
C 1
Selected Answer: C C. aaa new-model command turns on AAA globally, which is required for CoA to work on the device.