nerdexam
Cisco

300-715 · Question #353

What is a primary function of RADIUS compared to TACACS?

The correct answer is A. RADIUS provides AAA for network access, whereas TACACS provides AAA for device. RADIUS is primarily designed for network access authentication, authorization, and accounting, while TACACS+ provides more granular AAA services specifically for device administration.

Network Access Device Administration

Question

What is a primary function of RADIUS compared to TACACS?

Options

  • ARADIUS provides AAA for network access, whereas TACACS provides AAA for device
  • BRADIUS supports command accounting, whereas TACACS supports only start/stop accounting.
  • CRADIUS supports multiple privilege levels, whereas TACACS supports only one privilege level.
  • DRADIUS supports command authorization, whereas TACACS provides no support for commands.

How the community answered

(25 responses)
  • A
    96% (24)
  • B
    4% (1)

Why each option

RADIUS is primarily designed for network access authentication, authorization, and accounting, while TACACS+ provides more granular AAA services specifically for device administration.

ARADIUS provides AAA for network access, whereas TACACS provides AAA for deviceCorrect

RADIUS (Remote Authentication Dial-In User Service) is widely used for network access control (e.g., 802.1X, VPNs) to authenticate users and devices, whereas TACACS+ (Terminal Access Controller Access-Control System Plus) is specifically tailored for granular administrative access and command authorization on network devices like routers and switches.

BRADIUS supports command accounting, whereas TACACS supports only start/stop accounting.

TACACS+ provides extensive and granular command accounting, allowing detailed logging of individual commands executed by administrators, which is more comprehensive than RADIUS's typically limited start/stop session accounting.

CRADIUS supports multiple privilege levels, whereas TACACS supports only one privilege level.

TACACS+ fully supports multiple privilege levels and offers robust command authorization capabilities, enabling administrators to execute specific commands based on their assigned privilege level, unlike RADIUS which has limited support for device administration privilege levels.

DRADIUS supports command authorization, whereas TACACS provides no support for commands.

TACACS+ is renowned for its granular command authorization features, allowing explicit control over which commands an administrator can execute, a capability that RADIUS lacks or provides in a very limited fashion.

Concept tested: RADIUS vs. TACACS+ Features and Use Cases

Source: https://www.cisco.com/c/en/us/products/security/radius-vs-tacacs.html

Topics

#RADIUS#TACACS+#AAA protocols#Network Access vs. Device Admin

Community Discussion

No community discussion yet for this question.

Full 300-715 Practice