Soru

Zorluk: OrtaAuthentication, Authorization, and Accounting (AAA)

A systems administrator is reviewing federated identity access logs for an enterprise web portal. After a user successfully validates their username, password, and time-based one-time password (TOTP) at the central Identity Provider (IdP), the service provider parses the group membership claims in the token to restrict the user to read-only privileges on administrative dashboards. Which pillar of the AAA framework is being executed by the service provider when enforcing these access privileges based on group membership?

  1. AuthorizationCevap
  2. B
    Authentication
  3. C
    Accounting
  4. D
    Non-repudiation

Cevap

Authorization
Authorization is the AAA function responsible for evaluating rules and permissions to determine what resources or capabilities an authenticated identity may access. Restricting a user to read-only access based on group claims in a federated token is a classic application of authorization.

Adım Adım Çözüm

1
Identify the primary action being evaluated in the scenario.
The service provider evaluates token claims to grant specific privileges (read-only administrative dashboard access).
Assigning and restricting permissions based on verified roles or attributes defines how privileges are governed.
2
Map the identified action to the AAA framework components.
Credential validation is Authentication; permission evaluation is Authorization; logging and audit metrics is Accounting.
Because the step enforces what the user can do after identity confirmation, it falls under Authorization.

Anahtar Kavram

Authentication, Authorization, and Accounting (AAA)
Bu soruyu puanla