200-301 · Question #744
Which two statements about TACACS+ are true? (Choose two.)
The correct answer is A. It can run on a UNIX server. E. It uses a managed database. This question asks for two correct statements describing TACACS+ protocol characteristics.
Question
Options
- AIt can run on a UNIX server.
- BIt authenticates against the user database on the local device.
- CIt is more secure than AAA authentication.
- DIt is enabled on Cisco routers by default.
- EIt uses a managed database.
How the community answered
(55 responses)- A95% (52)
- B2% (1)
- C4% (2)
Why each option
This question asks for two correct statements describing TACACS+ protocol characteristics.
TACACS+ is an open standard that can be implemented on various operating systems, including UNIX servers, where TACACS+ daemons and databases can reside.
TACACS+ is designed for centralized authentication against a remote server, not against the local device's user database.
While TACACS+ offers strong security (e.g., full packet encryption), AAA is an architectural framework, and TACACS+ is an implementation of AAA, making this comparison imprecise.
TACACS+ is not enabled on Cisco routers by default; it requires explicit configuration.
TACACS+ servers typically use a centralized, managed database to store user credentials and detailed authorization policies, providing robust control and easier administration.
Concept tested: TACACS+ protocol characteristics
Source: https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/security/a1/sec-a1-cr-book/sec-cr-a1-chap-1.html
Topics
Community Discussion
No community discussion yet for this question.