nerdexam
Cisco

400-007 · Question #230

Company XYZ uses an office model where the employees can use any open desk and plug their laptops in. They want to authenticate the end users using their domain username and password before allowing…

The correct answer is D. RADIUS. RADIUS is the correct choice because it supports 802.1X-based end-user authentication against Active Directory and carries the vendor-specific attributes required for future macro and micro segmentation.

Designing Security

Question

Company XYZ uses an office model where the employees can use any open desk and plug their laptops in. They want to authenticate the end users using their domain username and password before allowing them access to the network. The design must also accommodate the ability of controlling traffic within the same group or subnet if a macro (or micro) segmentation-based model is adopted in the future. Which protocol can be recommended for this design to authenticate end users?

Options

  • ALDAP
  • BEAP
  • CTACACS+
  • DRADIUS

How the community answered

(51 responses)
  • A
    6% (3)
  • B
    8% (4)
  • C
    16% (8)
  • D
    71% (36)

Why each option

RADIUS is the correct choice because it supports 802.1X-based end-user authentication against Active Directory and carries the vendor-specific attributes required for future macro and micro segmentation.

ALDAP

LDAP is a directory query protocol used to look up credentials but is not a network access control protocol and cannot enforce port-based authentication or carry segmentation policy attributes to the network device.

BEAP

EAP is an authentication framework that must be encapsulated within a carrier protocol such as RADIUS to reach a network access server; it cannot operate independently as a network access authentication solution.

CTACACS+

TACACS+ is designed for device administration, command authorization, and management plane access on network infrastructure, not for authenticating end-user workstations seeking data plane network access.

DRADIUSCorrect

RADIUS integrates with 802.1X to authenticate end users via domain username and password against Active Directory, suiting a hot-desking environment where any port must validate the user. It also supports vendor-specific attributes such as VLAN assignment and Cisco TrustSec Security Group Tags (SGTs), which provide the per-user or per-group policy hooks needed for future macro or micro segmentation without a redesign.

Concept tested: RADIUS with 802.1X for end-user network access authentication

Source: https://www.cisco.com/c/en/us/tech/security/radius-authorization/index.html

Topics

#RADIUS#network access control#802.1X#micro segmentation

Community Discussion

No community discussion yet for this question.

Full 400-007 Practice