Soru

Zorluk: OrtaAAA Framework and Authentication Methods

A network security administrator is evaluating centralized AAA protocols to manage enterprise infrastructure. The design requires implementing TACACS+ for device administration and RADIUS for network access control. Which TWO of the following characteristics accurately differentiate the operational behavior of TACACS+ from RADIUS? (Select TWO.)

  1. TACACS+ decouples authentication and authorization into independent processes, whereas RADIUS combines authentication and authorization into a single exchange.Cevap
  2. TACACS+ encrypts the entire payload of the packet during transmission, whereas RADIUS encrypts only the password attribute within the packet.Cevap
  3. C
    TACACS+ relies on UDP port 49 as its primary transport protocol, whereas RADIUS operates exclusively over TCP port 1812.
  4. D
    RADIUS provides per-command authorization for router administrative sessions, whereas TACACS+ is primarily used for 802.1X port-based network access.

Cevap

The correct selections state that TACACS+ decouples authentication and authorization while RADIUS combines them, and that TACACS+ encrypts the entire packet body while RADIUS encrypts only the password field.
TACACS+ is a Cisco-proprietary/standardized administrative protocol that operates over TCP port 49, separating authentication and authorization while encrypting the entire packet payload. In contrast, RADIUS is an open standard operating over UDP ports 1812 and 1813 that combines authentication and authorization into single transactions and encrypts only the password attribute.

Adım Adım Çözüm

1
Analyze AAA architecture decoupling
Identify that TACACS+ separates AAA functions into independent modules, permitting per-command authorization, whereas RADIUS binds authentication and authorization together.
This is a core architectural difference between RADIUS and TACACS+.
2
Evaluate cryptographic boundary differences
Confirm that TACACS+ encrypts the full body of every packet, while RADIUS obfuscates only the password attribute.
Security boundary requirements specify full payload privacy for device administration sessions using TACACS+.
3
Verify transport layer protocol assignments
Rule out transport misidentifications by recalling TACACS+ uses TCP port 49 and RADIUS uses UDP ports 1812/1813.
Distinguishing connection-oriented (TCP) vs connectionless (UDP) transport is vital for AAA firewall configuration.

Anahtar Kavram

AAA Protocol Differentiation (RADIUS vs TACACS+)
Bu soruyu puanla