Soru

Zorluk: OrtaAAA Framework Concepts (Authentication, Authorization, Accounting)

An enterprise network operations team is evaluating centralized security protocols for authenticating and managing access across core infrastructure devices. Which TWO operational characteristics distinguish TACACS+ from RADIUS? (Select TWO.)

  1. TACACS+ operates over connection-oriented TCP port 49, whereas RADIUS utilizes connectionless UDP ports 1812 and 1813.Cevap
  2. B
    TACACS+ restricts encryption to only the password field in access request frames, whereas RADIUS encrypts the entire body of the packet.
  3. TACACS+ modularly decouples authentication from authorization, whereas RADIUS merges authentication and authorization into unified packet flows.Cevap
  4. D
    TACACS+ is the standard protocol for 802.1X port-based network authentication, whereas RADIUS is designed exclusively for network device CLI session control.

Cevap

TACACS+ operates over TCP port 49 while RADIUS uses UDP ports 1812 and 1813, and TACACS+ modularly decouples authentication from authorization while RADIUS merges them into unified packet flows.
TACACS+ uses connection-oriented TCP port 49 and provides modular separation of authentication and authorization functions, allowing granular control over administrative commands. In contrast, RADIUS uses UDP ports 1812/1813 and combines authentication and authorization.

Adım Adım Çözüm

1
Analyze transport protocol selection and default port assignments for TACACS+ and RADIUS.
TACACS+ uses TCP port 49 for reliable packet transport, while RADIUS operates over UDP using port 1812 for authentication/authorization and port 1813 for accounting.
TCP guarantees receipt notification and session establishment, which is suited for device management traffic.
2
Compare functional architecture and separation of AAA pillars across both protocols.
TACACS+ separates authentication, authorization, and accounting into distinct mechanisms, whereas RADIUS combines authentication and authorization into unified exchanges.
Decoupling authorization from authentication allows granular per-command permissions during active CLI administration sessions.

Anahtar Kavram

Protocol mechanics and functional differences between TACACS+ and RADIUS in enterprise AAA implementations.
Bu soruyu puanla