Soru

Zorluk: OrtaAAA Framework and Authentication Methods

A network administrator is configuring centralized administration for network switches. The organization's security policy mandates that every CLI command executed by administrators must be individually authorized and audited, and all traffic between the switch and authentication server must be completely encrypted. Which authentication protocol should the administrator deploy to satisfy these requirements?

  1. TACACS+Cevap
  2. B
    RADIUS
  3. C
    802.1X
  4. D
    Kerberos

Cevap

TACACS+ is the correct choice because it encrypts the full packet payload and supports granular per-command authorization and accounting for network device administration.
TACACS+ (Terminal Access Controller Access-Control System Plus) separates authentication, authorization, and accounting functions. It encrypts the complete body of the packet for enhanced privacy and allows administrators to enforce per-command authorization rules on network devices.

Adım Adım Çözüm

1
Analyze the operational requirements from the scenario.
Identified two primary requirements: full packet encryption and per-command CLI authorization/auditing.
Centralized device administration requires AAA capabilities tailored for network hardware control.
2
Evaluate protocol payload encryption mechanisms.
TACACS+ encrypts the entire message body (payload), whereas RADIUS encrypts only the user password field.
Security compliance requires encrypting all administrative data passed across the network.
3
Evaluate command authorization granularity.
TACACS+ separates authorization from authentication, enabling command-by-command authorization, whereas RADIUS combines them.
Granular command control is necessary to restrict and audit individual administrative commands.

Anahtar Kavram

TACACS+ vs RADIUS for Network Device Administration
Tahmini Süre:1m 15s
Bu soruyu puanla