Free Cisco 350-701 Actual Exam Questions - Question 7 Discussion
DRAG DROP [Secure Network Access, Visibility, and Enforcement] Refer to the exhibit.
An engineer must configure a Cisco switch to perform PPP authentication via a TACACS server located at IP address 10.1.1.10. Authentication must fall back to the local database using the username LocalUser and password C1Sc0451069341l if the TACACS server is unreachable. Drag and drop the commands from the left onto the corresponding configuration steps on the right. 
The local user config must match the exact username and password before AAA fallback.
I’m going with the commands that set up both AAA authentication and define the local user first. Without the local user configured, fallback wouldn’t actually work, so those steps have to be early in the process.
The fallback to local DB means using AAA methods, so commands must include fallback config, not just TACACS.
C/D? I get why web usage controls (C) seem right since it deals with managing access, but user session restrictions (D) might also play a role in controlling access based on sessions tied to user identity. Still, D feels more about session time or resource limits, not specifically URL categories. So I’d stick closer to C because it directly mentions usage controls, which fits URL category filtering better.
This one’s tricky but I think C covers URL-based access controls best. C. web usage controls