Soru

Zorluk: OrtaAAA Framework and Authentication Methods

A network operations team is upgrading their device management infrastructure to implement centralized command-level access control on enterprise routers. They select TACACS+ over RADIUS to fulfill this security requirement. Which technical capability of TACACS+ directly supports restricting specific administrative commands on a per-user basis?

  1. The strict separation of authentication and authorization processes, paired with full packet payload encryption over TCPCevap
  2. B
    The binding of authentication and authorization into a unified protocol exchange over UDP port 49
  3. C
    The encapsulation of authentication attributes within Layer 2 EAPOL frames that encrypt only the user password
  4. D
    The encryption of only the password field within a TCP stream operating on destination port 1812

Cevap

The strict separation of authentication and authorization processes, paired with full packet payload encryption over TCP
TACACS+ decouples authentication, authorization, and accounting functions within the AAA framework. This separation allows network access devices to send individual authorization requests to the TACACS+ server for each CLI command an administrator attempts to execute. Additionally, TACACS+ operates over TCP port 49 and encrypts the entire packet payload, providing comprehensive security for administrative device management.

Adım Adım Çözüm

1
Analyze the requirement for per-command administrative authorization
Determine that granular command-level authorization requires decoupling authentication from authorization in the AAA architecture.
When authentication and authorization are combined, authorization happens once at login rather than dynamically per CLI command.
2
Compare RADIUS and TACACS+ AAA architecture features
TACACS+ decouples AAA components, allowing independent authorization requests for every CLI command entered by an administrator. RADIUS combines authentication and authorization.
Decoupled architecture in TACACS+ enables dynamic per-command authorization.
3
Evaluate protocol transport and encryption specifications
TACACS+ uses TCP port 49 and encrypts the entire body of the packet, whereas RADIUS uses UDP (ports 1812/1813) and encrypts only the password field.
Full payload encryption provides maximum confidentiality for sensitive administrative session traffic.

Anahtar Kavram

AAA Protocol Differentiation (RADIUS vs TACACS+)
Tahmini Süre:1m 30s
Bu soruyu puanla