300-715 · Question #353
What is a primary function of RADIUS compared to TACACS?
The correct answer is A. RADIUS provides AAA for network access, whereas TACACS provides AAA for device. RADIUS is primarily designed for network access authentication, authorization, and accounting, while TACACS+ provides more granular AAA services specifically for device administration.
Question
What is a primary function of RADIUS compared to TACACS?
Options
- ARADIUS provides AAA for network access, whereas TACACS provides AAA for device
- BRADIUS supports command accounting, whereas TACACS supports only start/stop accounting.
- CRADIUS supports multiple privilege levels, whereas TACACS supports only one privilege level.
- DRADIUS supports command authorization, whereas TACACS provides no support for commands.
How the community answered
(25 responses)- A96% (24)
- B4% (1)
Why each option
RADIUS is primarily designed for network access authentication, authorization, and accounting, while TACACS+ provides more granular AAA services specifically for device administration.
RADIUS (Remote Authentication Dial-In User Service) is widely used for network access control (e.g., 802.1X, VPNs) to authenticate users and devices, whereas TACACS+ (Terminal Access Controller Access-Control System Plus) is specifically tailored for granular administrative access and command authorization on network devices like routers and switches.
TACACS+ provides extensive and granular command accounting, allowing detailed logging of individual commands executed by administrators, which is more comprehensive than RADIUS's typically limited start/stop session accounting.
TACACS+ fully supports multiple privilege levels and offers robust command authorization capabilities, enabling administrators to execute specific commands based on their assigned privilege level, unlike RADIUS which has limited support for device administration privilege levels.
TACACS+ is renowned for its granular command authorization features, allowing explicit control over which commands an administrator can execute, a capability that RADIUS lacks or provides in a very limited fashion.
Concept tested: RADIUS vs. TACACS+ Features and Use Cases
Source: https://www.cisco.com/c/en/us/products/security/radius-vs-tacacs.html
Topics
Community Discussion
No community discussion yet for this question.