nerdexam
Cisco

300-730 · Question #172

An administrator is deciding which authentication protocol should be implemented for their upcoming Cisco AnyConnect deployment. A list of the security requirements from upper management are: the abil

The correct answer is B. RADIUS. RADIUS is the only listed protocol that supports all three required AnyConnect password management features: complexity enforcement, expiration warnings, and in-session password changes.

Remote Access VPN

Question

An administrator is deciding which authentication protocol should be implemented for their upcoming Cisco AnyConnect deployment. A list of the security requirements from upper management are: the ability to force AnyConnect users to use complex passwords such as C1Sc045!P35084!, warn users a few days before their password expires, and allow users to change their password during a remote access session. Which authentication protocol must be used to meet these requirements?

Options

  • ALDAPS
  • BRADIUS
  • CKerberos
  • DTACACS+

How the community answered

(15 responses)
  • A
    7% (1)
  • B
    73% (11)
  • C
    7% (1)
  • D
    13% (2)

Why each option

RADIUS is the only listed protocol that supports all three required AnyConnect password management features: complexity enforcement, expiration warnings, and in-session password changes.

ALDAPS

LDAPS can enforce password complexity through the directory, but it does not natively support in-session password changes for AnyConnect VPN users the way RADIUS with MS-CHAPv2 does.

BRADIUSCorrect

RADIUS integrates with Cisco ASA and AnyConnect to deliver full password lifecycle management by leveraging MS-CHAPv2 and backend directory integration. It enforces complex password policies, delivers expiration warnings to users before their passwords expire, and allows users to change their passwords during an active AnyConnect session. No other protocol in this list provides all three capabilities within a Cisco AnyConnect VPN deployment.

CKerberos

Kerberos is a ticket-based single sign-on protocol that does not provide password expiration warnings or support in-session password changes for AnyConnect remote access sessions.

DTACACS+

TACACS+ is designed for device administration AAA and lacks the VPN user password management capabilities - including expiration warnings and in-session password changes - required for an AnyConnect deployment.

Concept tested: AnyConnect RADIUS password management and expiration

Source: https://www.cisco.com/c/en/us/td/docs/security/asa/asa96/configuration/vpn/asa-96-vpn-config/vpn-remote-users.html

Topics

#Cisco AnyConnect#RADIUS#password expiry#authentication protocol

Community Discussion

No community discussion yet for this question.

Full 300-730 Practice