Soru

Zorluk: OrtaAAA Framework Concepts (Authentication, Authorization, Accounting)

Match each AAA framework component or protocol characteristic on the left with its correct functional description on the right.

  • AuthenticationVerifies user identity using credentials such as username and password before granting access.
  • AuthorizationDetermines which specific commands, services, or resources an authenticated user is permitted to execute or access.
  • AccountingTracks and logs network resource usage, active session durations, and executed commands for auditing purposes.
  • TACACS+ Payload SecurityEncrypts the entire packet body rather than restricting encryption solely to the password string.

Cevap

Authentication matches identity verification; Authorization matches permission control for commands and resources; Accounting matches activity logging and tracking; TACACS+ Payload Security matches encrypting the entire packet body.
Authentication verifies identity, Authorization controls access permissions and allowed CLI commands, Accounting logs user activity for security compliance, and TACACS+ encrypts the entire packet payload.

Adım Adım Çözüm

1
Identify the primary function of Authentication within the AAA framework.
Authentication answers 'Who are you?' by verifying user credentials such as usernames and passwords.
It acts as the initial control point to validate user identity prior to granting system entry.
2
Identify the primary function of Authorization.
Authorization answers 'What can you do?' by determining privilege levels and permitted commands.
Once identity is established, privilege boundaries dictate accessible resources.
3
Identify the primary function of Accounting.
Accounting answers 'What did you do?' by collecting statistics, command history, and session durations.
Security compliance mandates keeping track of active sessions and administrative actions.
4
Analyze TACACS+ encryption behavior.
TACACS+ encrypts the entire payload body of each frame sent over TCP port 49.
This provides end-to-end payload confidentiality, contrasting with RADIUS which encrypts only the password field.

Anahtar Kavram

AAA Framework Pillars and TACACS+ vs RADIUS Security Mechanics
Bu soruyu puanla