A network security technician is reviewing the AAA architecture for managing network switches. The design mandates that administrative command authorization must be handled independently from initial authentication, and all traffic between the network access server and the AAA server must encrypt the entire packet payload. Which protocol should be deployed to satisfy these security requirements?
- TACACS+Cevap
- BRADIUS
- C802.1X
- DSNMPv3
Cevap
TACACS+ is the correct choice because it decouples authentication from authorization and encrypts the entire packet payload between the client device and the server.
TACACS+ meets both criteria specified in the scenario. It completely separates authentication, authorization, and accounting functions—enabling granular per-command authorization—and encrypts the entire packet payload sent across the network.
Adım Adım Çözüm
Anahtar Kavram
TACACS+ vs RADIUS protocol capabilities and functional separation in the AAA framework
Tahmini Süre:1m 0s