Cisco CCNP Security Core (SCOR) 350-701Network SecurityHard
A security auditor is reviewing the access control policies for critical network infrastructure devices. The current policy allows administrators to log in using local accounts with static passwords configured on each device. The auditor recommends implementing a centralized authentication, authorization, and accounting (AAA) system. Which of the following AAA protocols is commonly used for device administration and offers granular command authorization?
- ATACACS+
- BLDAP
- CKerberos
- DRADIUS
Show answer & explanationAnswer & explanation
Correct answer: A. TACACS+
TACACS+ is a Cisco proprietary protocol widely used for device administration, offering separate and granular authentication, authorization, and accounting, with a strong focus on command authorization, which is a key requirement here.
Why the other options are wrong
- B. LDAP is a directory service protocol used for storing and retrieving information, including user identities, but is not an AAA protocol itself for device administration.
- C. Kerberos is a network authentication protocol that uses tickets for authentication, primarily in Microsoft Active Directory environments, not typically for granular device administration AAA.
- D. RADIUS is an open standard, widely used for network access (e.g., Wi-Fi, VPN) and combines AAA into one process, but offers less granular command authorization than TACACS+.
TACACS+
TACACS+ (Terminal Access Controller Access-Control System Plus) is a Cisco proprietary AAA protocol that provides separate authentication, authorization, and accounting services, offering granular command authorization for network devices.
- Uses TCP port 49.
- Encrypts the entire packet body.
- Separates AAA functions, allowing independent control.
- Ideal for granular command authorization on network devices.
Memory trick: TACACS+: 'T' for 'Total' control over 'A'dmin commands.