200-301 · Question #653
Drag and Drop Question Drag and drop the functions of AAA supporting protocols from the left onto the protocols on the right. Answer:
The correct answer is encrypts only the password when it sends an access request; uses UDP; combines authentication and authorization; encrypts the entire body of the access-request packet; separates all three AAA operations; uses TCP. RADIUS (Remote Authentication Dial-In User Service) encrypts only the password in the access-request packet, uses UDP for transport, and combines authentication and authorization into a single process. TACACS+ (Terminal Access Controller Access-Control System Plus) encrypts the e
Question
Exhibit
Answer Area
Drag items
Correct arrangement
- encrypts only the password when it sends an access request
- uses UDP
- combines authentication and authorization
- encrypts the entire body of the access-request packet
- separates all three AAA operations
- uses TCP
Explanation
RADIUS (Remote Authentication Dial-In User Service) encrypts only the password in the access-request packet, uses UDP for transport, and combines authentication and authorization into a single process. TACACS+ (Terminal Access Controller Access-Control System Plus) encrypts the entire body of every packet for greater security, separates all three AAA operations (authentication, authorization, and accounting) independently, and uses TCP for reliable transport. These distinctions are fundamental to understanding when to choose each protocol - TACACS+ is preferred in Cisco device administration scenarios requiring granular command authorization, while RADIUS is commonly used for network access authentication.
Topics
Community Discussion
No community discussion yet for this question.
