nerdexam
EC-Council

312-50V13 · Question #336

An Internet Service Provider (ISP) has a need to authenticate users connecting via analog modems, Digital Subscriber Lines (DSL), wireless data services, and Virtual Private Networks (VPN) over a…

The correct answer is D. RADIUS. RADIUS is the Best Fit for ISP AAA Needs RADIUS (Remote Authentication Dial-In User Service) was specifically designed for ISP environments to authenticate large volumes of remote users across diverse connection types - including dial-up/analog modems, DSL, wireless, and VPN…

Submitted by saadiq_pk· Mar 6, 2026System Hacking

Question

An Internet Service Provider (ISP) has a need to authenticate users connecting via analog modems, Digital Subscriber Lines (DSL), wireless data services, and Virtual Private Networks (VPN) over a Frame Relay network. Which AAA protocol is the most likely able to handle this requirement?

Options

  • ATACACS+
  • BDIAMETER
  • CKerberos
  • DRADIUS

How the community answered

(35 responses)
  • A
    3% (1)
  • B
    6% (2)
  • D
    91% (32)

Explanation

RADIUS is the Best Fit for ISP AAA Needs

RADIUS (Remote Authentication Dial-In User Service) was specifically designed for ISP environments to authenticate large volumes of remote users across diverse connection types - including dial-up/analog modems, DSL, wireless, and VPN - making it the ideal protocol here. RADIUS is the industry standard for network access authentication and is natively supported by virtually all remote access equipment, including NAS (Network Access Servers) used in Frame Relay environments.

Why the distractors are wrong:

  • TACACS+ is a Cisco-proprietary protocol optimized for device administration (managing routers, switches) rather than mass user network access authentication
  • DIAMETER is technically RADIUS's more advanced successor, but it was not yet widely deployed in traditional ISP infrastructures at the time this scenario was commonly tested, and the question implies a classic ISP setup
  • Kerberos is a ticket-based authentication protocol designed for internal network/domain environments (like Windows Active Directory), not remote access over heterogeneous WAN connections

Memory Tip: Think RADIUS = Remote Access Dial-In Users - the name itself tells you it was built for exactly this use case. If you see an ISP authenticating end users connecting remotely, think RADIUS. If you see administrators managing network devices, think TACACS+.

Topics

#AAA protocols#RADIUS#Authentication#ISP networking

Community Discussion

No community discussion yet for this question.

Full 312-50V13 Practice