H12-725_V4.0 · Question #148
NAC (Network Access Control) is an "end-to-end" security technology that needs to cooperate with AAA to jointly realize the access authentication function. Which of the following descriptions of NAC…
The correct answer is B. The AAA server controls the access rights of access users by authenticating, authorizing, and C. NAC mainly includes three authentication methods: 802.1X authentication, MAC authentication D. NAC is mainly used for the interaction process between the access device and the authentication. Options B, C, and D correctly describe the division of responsibilities between AAA and NAC. B is correct because the AAA server's core function is to control user access by performing Authentication (verifying identity), Authorization (granting permissions), and Accounting…
Question
NAC (Network Access Control) is an "end-to-end" security technology that needs to cooperate with AAA to jointly realize the access authentication function. Which of the following descriptions of NAC and AAA are correct? (Multiple choice)
Options
- AAAA is mainly used for the interaction process between users and access devices
- BThe AAA server controls the access rights of access users by authenticating, authorizing, and
- CNAC mainly includes three authentication methods: 802.1X authentication, MAC authentication
- DNAC is mainly used for the interaction process between the access device and the authentication
How the community answered
(27 responses)- A22% (6)
- B78% (21)
Explanation
Options B, C, and D correctly describe the division of responsibilities between AAA and NAC. B is correct because the AAA server's core function is to control user access by performing Authentication (verifying identity), Authorization (granting permissions), and Accounting (tracking usage) - that is literally what AAA stands for and does. C is correct because NAC's three primary authentication methods are 802.1X (port-based), MAC authentication (by device hardware address), and Portal authentication (web-based captive portal). D is correct because NAC governs the communication layer between the access device (switch/router) and the authentication server, enforcing policy at that boundary.
Option A is the distractor to watch. It swaps the roles: it claims AAA handles user-to-access-device interaction, but that layer belongs to NAC. AAA operates on the backend - between the access device and the AAA server - not on the user-facing side.
Memory tip: Picture two handshakes - the user shakes hands with the access device (NAC's side), then the access device shakes hands with the AAA server (AAA's side). NAC = three doors to get in (802.1X, MAC, Portal); AAA = the gatekeeper behind those doors who checks your ID, grants your pass, and logs your visit.
Topics
Community Discussion
No community discussion yet for this question.