H12-725_V4.0 · Question #169
Which of the following descriptions of LDAP and AD authentication are correct? (Multiple choice)
The correct answer is A. The AD server is a server that integrates Kerberos and LDAP authentication. B. AD authentication integrates the Kerberos protocol based on LDAP D. iMaster can be used in LDAP authentication architecture. Options A and B are correct because Active Directory is fundamentally built on LDAP as its directory protocol, with Kerberos layered on top to handle the actual authentication - so AD is accurately described both as a server that integrates both protocols (A) and as a system…
Question
Which of the following descriptions of LDAP and AD authentication are correct? (Multiple choice)
Options
- AThe AD server is a server that integrates Kerberos and LDAP authentication.
- BAD authentication integrates the Kerberos protocol based on LDAP
- CLDAP authentication supports network devices to interact directly with the LDAP server
- DiMaster can be used in LDAP authentication architecture
How the community answered
(24 responses)- A79% (19)
- C21% (5)
Explanation
Options A and B are correct because Active Directory is fundamentally built on LDAP as its directory protocol, with Kerberos layered on top to handle the actual authentication - so AD is accurately described both as a server that integrates both protocols (A) and as a system that integrates Kerberos based on LDAP (B); these two statements describe the same relationship from slightly different angles.
Option D is correct because Huawei's iMaster network management platform supports LDAP authentication and can serve as an intermediary in an LDAP authentication architecture, relaying authentication requests on behalf of network devices.
Option C is the distractor - in standard LDAP authentication architectures, network devices do not interact directly with the LDAP server; instead, they send authentication requests to an AAA server (such as a RADIUS server), which then queries the LDAP server on their behalf. Direct device-to-LDAP communication is not the supported model.
Memory tip: Think of AD as a two-layer cake - LDAP is the base layer (directory storage and queries), and Kerberos is the top layer (authentication tickets). iMaster fits in as a Huawei-ecosystem middleman. For C, remember the rule: network devices talk to AAA/RADIUS, not directly to LDAP.
Topics
Community Discussion
No community discussion yet for this question.