300-730 · Question #172
An administrator is deciding which authentication protocol should be implemented for their upcoming Cisco AnyConnect deployment. A list of the security requirements from upper management are: the abil
The correct answer is B. RADIUS. RADIUS is the only listed protocol that supports all three required AnyConnect password management features: complexity enforcement, expiration warnings, and in-session password changes.
Question
Options
- ALDAPS
- BRADIUS
- CKerberos
- DTACACS+
How the community answered
(15 responses)- A7% (1)
- B73% (11)
- C7% (1)
- D13% (2)
Why each option
RADIUS is the only listed protocol that supports all three required AnyConnect password management features: complexity enforcement, expiration warnings, and in-session password changes.
LDAPS can enforce password complexity through the directory, but it does not natively support in-session password changes for AnyConnect VPN users the way RADIUS with MS-CHAPv2 does.
RADIUS integrates with Cisco ASA and AnyConnect to deliver full password lifecycle management by leveraging MS-CHAPv2 and backend directory integration. It enforces complex password policies, delivers expiration warnings to users before their passwords expire, and allows users to change their passwords during an active AnyConnect session. No other protocol in this list provides all three capabilities within a Cisco AnyConnect VPN deployment.
Kerberos is a ticket-based single sign-on protocol that does not provide password expiration warnings or support in-session password changes for AnyConnect remote access sessions.
TACACS+ is designed for device administration AAA and lacks the VPN user password management capabilities - including expiration warnings and in-session password changes - required for an AnyConnect deployment.
Concept tested: AnyConnect RADIUS password management and expiration
Source: https://www.cisco.com/c/en/us/td/docs/security/asa/asa96/configuration/vpn/asa-96-vpn-config/vpn-remote-users.html
Topics
Community Discussion
No community discussion yet for this question.