400-007 · Question #230
Company XYZ uses an office model where the employees can use any open desk and plug their laptops in. They want to authenticate the end users using their domain username and password before allowing…
The correct answer is D. RADIUS. RADIUS is the correct choice because it supports 802.1X-based end-user authentication against Active Directory and carries the vendor-specific attributes required for future macro and micro segmentation.
Question
Company XYZ uses an office model where the employees can use any open desk and plug their laptops in. They want to authenticate the end users using their domain username and password before allowing them access to the network. The design must also accommodate the ability of controlling traffic within the same group or subnet if a macro (or micro) segmentation-based model is adopted in the future. Which protocol can be recommended for this design to authenticate end users?
Options
- ALDAP
- BEAP
- CTACACS+
- DRADIUS
How the community answered
(51 responses)- A6% (3)
- B8% (4)
- C16% (8)
- D71% (36)
Why each option
RADIUS is the correct choice because it supports 802.1X-based end-user authentication against Active Directory and carries the vendor-specific attributes required for future macro and micro segmentation.
LDAP is a directory query protocol used to look up credentials but is not a network access control protocol and cannot enforce port-based authentication or carry segmentation policy attributes to the network device.
EAP is an authentication framework that must be encapsulated within a carrier protocol such as RADIUS to reach a network access server; it cannot operate independently as a network access authentication solution.
TACACS+ is designed for device administration, command authorization, and management plane access on network infrastructure, not for authenticating end-user workstations seeking data plane network access.
RADIUS integrates with 802.1X to authenticate end users via domain username and password against Active Directory, suiting a hot-desking environment where any port must validate the user. It also supports vendor-specific attributes such as VLAN assignment and Cisco TrustSec Security Group Tags (SGTs), which provide the per-user or per-group policy hooks needed for future macro or micro segmentation without a redesign.
Concept tested: RADIUS with 802.1X for end-user network access authentication
Source: https://www.cisco.com/c/en/us/tech/security/radius-authorization/index.html
Topics
Community Discussion
No community discussion yet for this question.