Soru

Zorluk: OrtaAAA Framework Concepts (Authentication, Authorization, Accounting)

A network security administrator is configuring centralized security management for enterprise switches and routers. Match each AAA pillar or protocol characteristic on the left with its correct operational description on the right.

  • AuthenticationVerifies identity using credentials such as username and password before granting access.
  • AuthorizationDetermines the specific commands, services, and privilege levels an identified user is allowed to execute.
  • AccountingTracks and logs resource utilization, session duration, and specific executed commands for auditing purposes.
  • TACACS+ Security ArchitectureEncrypts the entire payload of the packet and separatesAAA functions using TCP port 49.

Cevap

Authentication matches with verifying user credentials. Authorization matches with defining allowed privileges and commands. Accounting matches with logging user activity and session details. TACACS+ Security Architecture matches with encrypting the full payload and separating AAA functions over TCP port 49.
Authentication verifies credentials (who you are), Authorization controls permitted actions/commands (what you can do), Accounting logs user session details (what you did), and TACACS+ architecture relies on TCP port 49 while providing full-packet payload encryption and modular separation of AAA functions.

Adım Adım Çözüm

1
Identify the core definition of Authentication
Authentication answers 'Who are you?' by verifying credentials such as usernames and passwords.
Establishing identity is the primary first step in the AAA framework.
2
Identify the core definition of Authorization
Authorization answers 'What can you do?' by defining permitted command levels and access rights.
Once identity is proven, permissions must be enforced per user role.
3
Identify the core definition of Accounting
Accounting answers 'What did you do?' by tracking session start/stop times and commands executed.
Auditing requires keeping log records of user actions.
4
Identify the architectural mechanics of TACACS+
TACACS+ decouples AAA operations and uses TCP port 49 with full-packet payload encryption.
Unlike RADIUS which combines authentication/authorization and encrypts passwords only, TACACS+ provides total payload encryption and modular AAA separation.

Anahtar Kavram

AAA Framework Pillars and TACACS+ Protocol Architecture
Bu soruyu puanla