Which Two Methods Belong in an AAA Authentication Method List?

Cisco IOS AAA Authentication
Answer Correct answer: D, E — In a Cisco IOS AAA authentication method list, line and enable are valid method keywords, while default names the list and login applies it.

Which two methods are valid to be included in an authentication method list? (Choose two.)

  1. default
  2. login
  3. console
  4. line Correct Answer
  5. enable Correct Answer

Community Votes

DE
63%
BE
37%

63% of anonymous learners picked answer DE. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

It tests Cisco AAA command grammar — separating method-list names (default) and service keywords (login) from actual method keywords (line, enable) — and the trap is treating login or console as methods.

This Cisco 350-701 question tests which keywords are valid methods inside a Cisco IOS AAA authentication method list. The page confirms that line and enable (D, E) are the correct choices, while default, login, and console are not methods.

Most learners who miss choose B (login) or C (console); login is the service keyword that applies the method list to line access, and console is a line type, not an authentication method keyword.

Community Discussion (7 comments)

NullNull88 👍 1 Selected: DE
d and e are correct
JRKhan 👍 1 Selected: DE
line and enable are the valid methods available in the default list in addition to local and group (tacacs+ or radius)
Pierre_Bouvier 👍 1 Selected: AE
The login keyword is not an authentication method itself. It is used to apply the authentication method list to a line, but it does not belong within the list of methods.
PMVJ 👍 1 Selected: BE
The question is asking about the authentication method list and what methods are valid. Line refers to the configuration of the relevant "line" (console, aux, vty, etc) where the authentication method list will be applied and not to the method being applied to the authentication method list https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_usr_aaa/configuration/15-sy/sec-usr-aaa-15-sy-book/sec-cfg-authentifcn.html#GUID-B6D7796C-56F3-46A5-8FF4-0F625D8FBCE8
Mcdeedee 👍 1
Not Console and Line ?
dfb0b7d 👍 3 Selected: DE
Line: Uses the line password for authentication. Enable: Uses the enable password for authentication. https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/sec_usr_aaa/configuration/15-sy/sec-usr-aaa-15-sy-book/sec-cfg-authentifcn.html
klu16 👍 2 Selected: BE
Correct.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

In Cisco IOS AAA, the command syntax is aaa authentication login <list-name> <method1> <method2>..., and the method keywords accepted after the list name include enable, local, line, none, group radius, group tacacs+, if-authenticated, and krb5. The line method uses the configured line password (for example, the vty or console line password) for authentication, and enable uses the enable password. Therefore, among the listed options, only line and enable are valid methods that can be included in an authentication method list. The question asks for keywords that belong inside the list, not the name of the list or the service to which it is applied.

Why the Other Options Are Wrong

Option A (default) is a reserved method-list name that is used when no named list is applied to the login service; it is not a method keyword. Option B (login) is the service keyword in aaa authentication login, so it names and applies the method list to line access rather than being a method itself. Option C (console) is a line type (like aux or vty), not an authentication method keyword. Selecting B confuses the command's service keyword with a method, and selecting C mistakes a physical or virtual line type for a method.

Community Comment Notes

As dfb0b7d explains, "Line: Uses the line password for authentication" and "Enable: Uses the enable password for authentication," pointing to the Cisco AAA command reference. JRKhan adds that "line and enable are the valid methods available in the default list" alongside local and group methods. Pierre_Bouvier correctly notes that "The login keyword is not an authentication method itself," while PMVJ argues that line refers to the line configuration rather than the method applied to the list — but Cisco's documented method keyword line is exactly that: a method source. The vote split (DE 56 vs BE 33) shows many learners still confuse the service keyword with a method.

Official Reference

Exam Strategy

Memorize the Cisco AAA command grammar: after aaa authentication login, the first token is the method-list name (default or a custom name), and every token after it must be a method keyword. If an option describes a service (login), a list name (default), or a line type (console), it cannot be a method. For this two-answer question, look for the pair that maps to password sources, line and enable.

Frequently Asked Questions

Why is login not a valid method in the authentication method list?

In aaa authentication login, login is the service keyword that names and applies the method list to line access; it is not itself a method. Valid method keywords include line, enable, local, group, and none.

Why can't default be selected as one of the two methods?

default is the reserved method-list name used when no named list is applied to the login service. It appears before the method keywords, so it cannot be one of the methods inside the list.

Related Analysis

← Back to 350-701 Study Guide