CompTIA Network+ (N10-009)Network SecurityMedium

A network administrator wants a AAA solution for administering network devices that encrypts the entire authentication packet and separates authentication, authorization, and accounting into distinct processes, allowing granular control over which commands each administrator can execute on a router. Which protocol best meets this requirement?

  1. ALDAP
  2. BKerberos
  3. CTACACS+
  4. DRADIUS
Show answer & explanation

Correct answer: C. TACACS+

TACACS+ encrypts the entire packet payload and separates authentication, authorization, and accounting, enabling command-level authorization ideal for device administration. RADIUS only encrypts the password and combines authentication/authorization; Kerberos and LDAP are not AAA protocols designed for device command authorization.

Why the other options are wrong

  • A. LDAP is a directory access protocol, not an AAA/command-authorization protocol.
  • B. Kerberos is a ticket-based authentication protocol, not a full AAA solution for device commands.
  • D. RADIUS combines authentication and authorization and encrypts only the password field.

TACACS+

A Cisco-developed AAA protocol that fully encrypts authentication traffic and separates authentication, authorization, and accounting, commonly used for granular administrative control of network devices.

  • Uses TCP port 49
  • Encrypts the entire packet, not just the password
  • Allows per-command authorization for device administration

Memory trick: TACACS+ Tackles All Commands Carefully, Separately.

More Network Security questions