Implementing AAA in Cisco IOS Flashcards

1
Q

What is most likely used for authentication of a network administrator accessing the CLI of a Cisco router?

A

TACACS, ACS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What allows for granular control related to authorization of specific Cisco IOS commands that are being attempted by an authenticated and authorized Cisco router admin?

A

TACACS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Which devices or users would be clients of an ACS server?

A

Router, Switch

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

On the router, what should be created and applied to a vty line to enforce a specific set of methods for identifying who a user is?

A

Authorization method list

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is the minimum size for an effective TACACS group of servers?

A

1

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

With what can you configure AAA on the router?

A

CCP, CLI

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Which statement is true for ACS 5.x and later?

A

Authorization policies can be associated with user groups that are accessing specific network device groups.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Where in the ACS do you go to create a new group of administrators?

A

Users and Identity Stores > Identity Groups

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

From the router, which method tests the most about the ACS configuration, without forcing you to log in again at the router?

A

test aaa

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What could likely cause an ACS authentication failure, even when the user is using the correct credentials?

A

Incorrect secret on ACS, Incorrect IP address of the ACS server on the router, incorrect routing, incorrect filtering between the ACS and router

How well did you know this?
1
Not at all
2
3
4
5
Perfectly