Soru

Zorluk: OrtaKey Security Concepts, Threats, Vulnerabilities, and Mitigations

An infrastructure analyst is performing a security review of an enterprise management network. The organization requires per-command authorization for administrative CLI access on routers and switches, along with full packet payload encryption between network devices and the central AAA server. Which security protocol satisfies these requirements?

  1. TACACS+, because it encrypts the entire packet payload and separates authentication, authorization, and accounting functions.Cevap
  2. B
    RADIUS, because it encrypts the entire packet payload and provides granular per-command authorization capabilities.
  3. C
    RADIUS, because it encrypts only the password field while separating authorization from authentication controls.
  4. D
    TACACS+, because it encrypts only the password field while operating natively over TCP port 49.

Cevap

TACACS+, because it encrypts the entire packet payload and separates authentication, authorization, and accounting functions.
TACACS+ operates over TCP port 49 and separates the authentication, authorization, and accounting (AAA) functions. This modular separation permits granular authorization checks for every individual administrative command entered on a network device. Furthermore, TACACS+ encrypts the full body of every packet after the standard header, meeting the requirement for complete payload confidentiality.

Adım Adım Çözüm

1
Analyze requirement 1: Full payload encryption.
TACACS+ encrypts the entire packet payload after the header, whereas RADIUS only encrypts the password attribute.
Security requirement demands full payload protection during network transmission.
2
Analyze requirement 2: Per-command authorization.
TACACS+ decouples authentication, authorization, and accounting, allowing every CLI command to be individually authorized by the TACACS+ server.
RADIUS binds authentication and authorization together, which prevents per-command authorization.
3
Select protocol matching both conditions.
TACACS+ meets both full payload encryption and granular per-command authorization criteria.
Only TACACS+ satisfies all architectural constraints.

Anahtar Kavram

TACACS+ vs RADIUS Protocol Characteristics and AAA Separation
Bu soruyu puanla