nerdexam
CompTIA

CAS-001 · Question #98

A network security engineer would like to allow authorized groups to access network devices with a shell restricted to only show information while still authenticating the administrator's group to…

The correct answer is E. RADIUS F. TACACS+. TACACS+ (F) and RADIUS (E) are AAA (Authentication, Authorization, Accounting) protocols used specifically for network device access control. TACACS+ is particularly well-suited for command authorization on network devices-it separates authentication, authorization, and…

Enterprise Security

Question

A network security engineer would like to allow authorized groups to access network devices with a shell restricted to only show information while still authenticating the administrator's group to an unrestricted shell. Which of the following can be configured to authenticate and enforce these shell restrictions? (Select TWO).

Options

  • ASingle Sign On
  • BActive Directory
  • CKerberos
  • DNIS+
  • ERADIUS
  • FTACACS+

How the community answered

(44 responses)
  • A
    2% (1)
  • B
    5% (2)
  • C
    14% (6)
  • D
    2% (1)
  • E
    77% (34)

Explanation

TACACS+ (F) and RADIUS (E) are AAA (Authentication, Authorization, Accounting) protocols used specifically for network device access control. TACACS+ is particularly well-suited for command authorization on network devices-it separates authentication, authorization, and accounting into distinct functions, enabling per-command shell restrictions for one group while granting unrestricted shell access to another. RADIUS also supports shell restrictions via vendor-specific attributes (VSAs) and privilege levels on Cisco and other devices. Active Directory (B) and Kerberos (C) handle authentication but do not natively enforce CLI shell restrictions on network devices. NIS+ (D) is a legacy Unix directory service. SSO (A) is a login methodology, not an AAA enforcement mechanism. TACACS+ is the preferred protocol for granular network device command authorization.

Topics

#RADIUS#TACACS+#AAA#network device access control

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice