
CiscoCertified Network Professional Enterprise
Domain 5Objective 1
5.1 Configure and Verify Device Access Control 350-401 Practice Questions (Page 2)
Part of the 5.0 Security domain, which accounts for 20% of the 350-401 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~10–16 in this domain), expect 3–4 from this objective — we provide 12 practice questions to prepare you well beyond it. (estimate)
12questions here
3free pages
4concepts
20%of the exam
Questions 6–10
- 6
Which AAA command enables authorization for all network-related services (such as PPP and SLIP) using the default method list?
Select an answer first - 7
Which AAA command is used to define a server group that includes a RADIUS server for use in authentication method lists?
Select an answer first - 8
A network team uses TACACS+ for authentication. They want to restrict which commands each administrator can run after login, based on their TACACS+ profile. Which AAA feature must be configured to enforce these per-command restrictions?
Select an answer first - 9
A network administrator wants to restrict which commands a user can execute in privileged EXEC mode based on the user's identity. Which AAA authorization command should be used?
Select an answer first - 10
A network engineer needs to secure the console port of a Cisco switch so that a password is required before the user can enter privileged EXEC mode. Which command sequence accomplishes this?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-401” is a trademark of its owner, used for identification only.