Cisco CCNA (200-301)Security FundamentalsMedium

A company wants remote administrators authenticated against a central AAA server, but once authenticated, wants the AAA server to also determine which specific IOS commands each administrator is permitted to run. Which AAA function accomplishes the command-level restriction?

  1. AAuditing
  2. BAccounting
  3. CAuthentication
  4. DAuthorization
Show answer & explanation

Correct answer: D. Authorization

Authorization is the AAA component that determines what an authenticated user is allowed to do, such as which commands they can execute. This is commonly implemented with 'aaa authorization commands' referencing a TACACS+ server, since TACACS+ supports granular command authorization.

Why the other options are wrong

  • A. Auditing is not one of the three AAA components (Authentication, Authorization, Accounting).
  • B. Accounting logs what actions were taken, but does not restrict them.
  • C. Authentication only verifies identity (username/password), not permitted actions.

AAA Authorization

Authorization is the AAA process that determines what resources or commands an authenticated user is permitted to access or execute.

  • Comes after authentication in the AAA model
  • TACACS+ supports per-command authorization
  • Configured with 'aaa authorization' statements

Memory trick: Authenticate WHO you are, Authorize WHAT you can do, Account for WHAT you did.

More Security Fundamentals questions