Soru

Zorluk: OrtaAAA Framework and Authentication Methods

A network security administrator is mapping enterprise authentication protocols and frameworks to their core operational characteristics. Match each authentication protocol or framework on the left with its correct operational description on the right.

  • TACACS+Encrypts the entire packet payload and separates authentication, authorization, and accounting into modular processes over TCP port 49.
  • RADIUSEncrypts only the password field by default and combines authentication and authorization functions over UDP ports 1812 and 1813.
  • KerberosUtilizes a Key Distribution Center (KDC) to issue ticket-granting tokens (TGT) for centralized single sign-on across a trusted domain.
  • 802.1XProvides port-based network access control by encapsulating Extensible Authentication Protocol (EAP) messages between a supplicant and an authenticator.

Cevap

TACACS+ matches full payload encryption over TCP port 49; RADIUS matches password-only encryption over UDP ports 1812/1813; Kerberos matches ticket-granting tokens for SSO; 802.1X matches port-based access control encapsulating EAP traffic.
Each protocol is accurately matched to its operational characteristics: TACACS+ encrypts the entire payload over TCP port 49 with decoupled AAA; RADIUS encrypts only passwords over UDP ports 1812/1813 with combined authentication/authorization; Kerberos uses a Key Distribution Center and tickets for SSO; and 802.1X provides port-level protection using EAP encapsulation.

Adım Adım Çözüm

1
Identify the transport protocol and encryption boundary for administrative device management.
Recognize that TACACS+ uses TCP port 49, separates AAA components, and encrypts the complete payload.
TACACS+ was engineered specifically for router/switch management where full command encryption and granular authorization are needed.
2
Identify the transport protocol and encryption behavior of network access AAA.
Associate RADIUS with UDP ports 1812/1813 and password-only encryption.
RADIUS combines authentication and authorization into single response packets while obfuscating only user credentials.
3
Examine token-based domain single sign-on protocols.
Link Kerberos to ticket-granting tokens and Key Distribution Centers.
Kerberos facilitates secure authentication across network services using mutual authentication and cryptographic tokens.
4
Analyze port-based network boundary enforcement mechanisms.
Pair 802.1X with EAP encapsulation at Layer 2.
802.1X prevents unauthorized network port access until an authentication server validates the supplicant's credentials.

Anahtar Kavram

AAA Framework and Centralized Authentication Protocols
Bu soruyu puanla