nerdexam
CompTIA

CAS-003 · Question #461

A company's security policy states any remote connections must be validated using two forms of network- based authentication. It also states local administrative accounts should not be used for any…

The correct answer is D. RADIUS E. LDAP. RADIUS (D) and LDAP (E) satisfy all the stated requirements. RADIUS is the standard authentication protocol supported by NGFWs for VPN access; it natively supports multi-factor authentication including RSA tokens, fulfilling the two-form authentication requirement without…

Technical Integration of Enterprise Security

Question

A company's security policy states any remote connections must be validated using two forms of network- based authentication. It also states local administrative accounts should not be used for any remote access. PKI currently is not configured within the network. RSA tokens have been provided to all employees, as well as a mobile application that can be used for 2FA authentication. A new NGFW has been installed within the network to provide security for external connections, and the company has decided to use it for VPN connections as well. Which of the following should be configured? (Choose two.)

Options

  • ACertificate-based authentication
  • BTACACS+
  • C802.1X
  • DRADIUS
  • ELDAP
  • FLocal user database

How the community answered

(25 responses)
  • B
    4% (1)
  • C
    12% (3)
  • D
    76% (19)
  • F
    8% (2)

Explanation

RADIUS (D) and LDAP (E) satisfy all the stated requirements. RADIUS is the standard authentication protocol supported by NGFWs for VPN access; it natively supports multi-factor authentication including RSA tokens, fulfilling the two-form authentication requirement without needing PKI. LDAP provides centralized directory-based authentication, supplying the second network-based authentication mechanism and enabling user lookups without relying on local administrative accounts. Certificate-based authentication (A) is eliminated because PKI is not configured. TACACS+ (B) is designed for device administration, not VPN user authentication. 802.1X (C) is a port-based network access control protocol, not a VPN authentication mechanism. A local user database (F) is explicitly prohibited by policy for remote access.

Topics

#VPN authentication#RADIUS#LDAP#multi-factor authentication

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice