Implementing and Operating Cisco Enterprise Network Core Technologies (ENCOR) v1.2SecurityEasy

A network security team is implementing a new policy to restrict administrative access to network devices. They want to ensure that only authorized personnel can log in and that their actions are recorded for auditing purposes. Which component of AAA is primarily responsible for determining what an authenticated user is permitted to do?

  1. AAuditing
  2. BAccounting
  3. CAuthentication
  4. DAuthorization
Show answer & explanation

Correct answer: D. Authorization

Authorization is the AAA component that defines what an authenticated user is allowed to do or access on a network device. It works after authentication has verified the user's identity.

Why the other options are wrong

  • A. Auditing is a separate process that reviews logs, not a direct AAA component.
  • B. Accounting tracks user activity, but does not define permissions.
  • C. Authentication verifies the user's identity, but not what they can do.

AAA Authorization

The AAA component that determines what an authenticated user is permitted to do on a network resource.

  • Occurs after successful authentication.
  • Defines access rights and permissions.
  • Can be rule-based or role-based.

Memory trick: AAA is like a security guard, a bouncer, and a time clock.

More Security questions