Soru

Zorluk: OrtaAAA Framework Concepts (Authentication, Authorization, Accounting)

An enterprise network policy mandates strict access controls for network engineers managing edge routers. The policy requires that user identity verification and command execution permission checks operate as completely decoupled processes, allowing individual CLI commands to be evaluated independently by a central server after a session is established. Which operational characteristic of TACACS+ satisfies this requirement?

  1. Complete separation of authentication, authorization, and accounting functions into distinct, modular transactionsCevap
  2. B
    Combination of authentication and authorization into a unified exchange using UDP transport
  3. C
    Encryption restricted exclusively to the password field while sending authorization headers in plaintext
  4. D
    Use of connectionless UDP port 49 to allow rapid asynchronous command verification bursts

Cevap

TACACS+ architecture fully decouples authentication, authorization, and accounting, which enables per-command authorization checks during an established administrative session over reliable TCP port 49.
TACACS+ separates authentication, authorization, and accounting into distinct functional processes and uses TCP port 49 for reliable transport. This modular separation enables network devices to send independent authorization requests for individual CLI commands executed during an active administrative session.

Adım Adım Çözüm

1
Analyze the policy requirements
The scenario requires decoupled authentication and authorization services to perform per-command authorization checks.
Administrative device access requires fine-grained control over which specific CLI commands a user can run.
2
Compare TACACS+ and RADIUS functional separation mechanics
TACACS+ separates AAA services into modular transactions over TCP port 49, whereas RADIUS combines authentication and authorization into unified transactions over UDP.
Modular functional separation allows a device to request authorization decisions for individual commands without re-authenticating.

Anahtar Kavram

TACACS+ vs. RADIUS Functional Architecture (Decoupled AAA vs. Combined Auth/Author)
Bu soruyu puanla