Cisco CCNA (200-301)Security FundamentalsHard
A security team is comparing AAA protocols for network device administration. They require an option that encrypts the entire packet payload (not just the password) and uses TCP for reliable delivery. Which protocol meets this requirement?
- AKerberos
- BTACACS+
- CRADIUS
- DSNMPv2
Show answer & explanationAnswer & explanation
Correct answer: B. TACACS+
TACACS+ encrypts the entire packet body and uses TCP port 49, providing more robust confidentiality for device administration traffic, whereas RADIUS only encrypts the password field and uses UDP.
Why the other options are wrong
- A. Kerberos is a ticket-based authentication protocol, not typically used for device AAA in this context.
- C. RADIUS uses UDP and encrypts only the password, not the whole packet.
- D. SNMPv2 is a network management protocol, not an AAA protocol.
TACACS+ vs RADIUS
TACACS+ is Cisco's AAA protocol that encrypts entire packets over TCP port 49; RADIUS encrypts only the password and uses UDP ports 1812/1813.
- TACACS+: TCP port 49, full packet encryption
- RADIUS: UDP 1812 (auth)/1813 (accounting), password-only encryption
- TACACS+ separates authentication, authorization, accounting
Memory trick: TACACS+ Totally Covers All the Content Securely