Soru

Zorluk: OrtaAAA Framework and Authentication Methods

A network security administrator is assessing the centralized access control deployment for an enterprise infrastructure. The administrator needs to evaluate the architectural and transport differences between RADIUS and TACACS+ protocols. Which of the following statements correctly distinguish TACACS+ from RADIUS? (Select TWO).

  1. TACACS+ encrypts the complete body of the transmission payload, whereas RADIUS encrypts only the user password attribute.Cevap
  2. TACACS+ decouples authentication, authorization, and accounting into distinct interactions, whereas RADIUS combines authentication and authorization into a single service exchange.Cevap
  3. C
    RADIUS relies on TCP port 49 to maintain persistent, connection-oriented sessions for administrative authentication.
  4. D
    TACACS+ uses connectionless UDP ports 1812 and 1813 to convey device management command authorization requests.

Cevap

The correct statements are that TACACS+ encrypts the complete packet payload while RADIUS encrypts only the password attribute, and TACACS+ decouples AAA functions whereas RADIUS combines authentication and authorization into a single exchange.
TACACS+ provides full-payload encryption past the header and modular separation of AAA functions, making it ideal for granular switch/router administration. RADIUS encrypts only the password attribute and combines authentication and authorization into unified transaction packets.

Adım Adım Çözüm

1
Analyze encryption boundaries for both protocols
TACACS+ encrypts the entire packet payload (except the header), whereas RADIUS encrypts only the user password field.
Security protocol specifications define different payload encryption scopes for TACACS+ versus RADIUS.
2
Evaluate AAA architectural separation
TACACS+ separates authentication, authorization, and accounting into granular, independent transactions, while RADIUS merges authentication and authorization into unified response messages.
TACACS+ was engineered specifically for granular device administration, requiring separate authorization queries per command.
3
Verify transport layer protocols and port numbers
TACACS+ uses TCP port 49, whereas RADIUS uses UDP ports 1812 (authentication) and 1813 (accounting).
This confirms that options suggesting RADIUS uses TCP 49 or TACACS+ uses UDP 1812/1813 are incorrect.

Anahtar Kavram

RADIUS vs TACACS+ Protocol Architecture and Security Boundaries
Bu soruyu puanla