- Home
- Networking
- CCNA Routing and Switching 200-125
101.
Which protocol will encrypt the entire packet from the switch or router to the
AAA server?
- A.802.1x
- B.IPSEC
- C.RADIUS
- D.TACACS+
- Answer & Explanation
- Report
Answer : [D]
Explanation :
Explanation :
The TACACS+ protocol will encrypt the entire packet from the switch or router to the AAA server. |
102.
Which command will configure the RADIUS server 192.168.1.5 with a secret of
aaaauth?
- A.Router(config)#radius host 192.168.1.5 key aaaauth
- B.Router(config)#radius-server host 192.168.1.5 key aaaauth
- C.Router(config)#radius-server 192.168.1.5 key aaaauth
- D.Router(config)#radius-server host 192.168.1.5 secret aaaauth
- Answer & Explanation
- Report
Answer : [B]
Explanation :
Explanation :
The command radius-server host 192.168.1.5 key aaaauth will configure the radius server 192.168.1.5 with a secret key of aaaauth. |
103.
Why should you always provide a second method of local when setting up AAA
remote authentication with a router or switch?
- A.To allow for a backdoor
- B.To provide a backup if the TACACS+ server is down or unreachable
- C.The local second method is required
- D.All of the above
- Answer & Explanation
- Report
Answer : [B]
Explanation :
Explanation :
The local second method should always be configured. This will ensure that if the router’s connection to the AAA server is down, you can still gain access to diagnose or repair. |
104.
You configured the AAA authentication for login to default local but forgot to
create a local AAA user. What will happen when you log out?
- A.The enable secret will work.
- B.The console will still be available.
- C.The router will lock you out.
- D.Nothing, since a username and password have not been set.
- Answer & Explanation
- Report
Answer : [C]
Explanation :
Explanation :
The router will lock you out since you have not provided a local account to log in with. The password recovery procedure would need to be performed if the configuration was saved. |
105.
Which command will configure the router to use a TACACS+ server and a backup
of local for authentication of logins?
- A.Router(config)#aaa authentication login default group tacacs+ local
- B.Router(config)#authentication login group tacacs+ local
- C.Router(config)#aaa-authentication login default tacacs+ local
- D.Router(config)#aaa authentication login tacacs+ local
- Answer & Explanation
- Report
Answer : [C]
Explanation :
Explanation :
The command aaa authentication login default group tacacs+ local will configure AAA authentication for login using the default list and a group of TACACS+ servers for TACACS+ login first and a backup of local for authentication. |